An Exploded View publication

Reading Room

Vol. 1 · No. 20 Tuesday, August 11, 2026 aikansh.com

This week's theme

The tools start acting without asking

This week the defaults change: Claude Code starts acting on its own, Anthropic marks what Claude makes, and OpenAI puts ads in front of free users.

A 16-minute read · 11 stories

In this issue

01 Front Page

Claude Code turns on auto mode by default Aug 14

It will act on its own more often, catching risky commands before they run instead of asking permission for each step.

Starting August 14, Claude Code will act on its own more often instead of asking permission for every step, and it is worth knowing what that switch actually does before it turns on for you.

Claude Code is Anthropic's coding tool, and up to now it has stopped to ask permission before many actions, like running a command or editing a file. From August 14, new sessions on the Pro, Max, and Team plans will run in auto mode by default. The feature stays opt-in for now on Claude Enterprise, the Claude API, and the big cloud platforms, AWS Bedrock, Google Cloud's Agent Platform, and Microsoft Foundry, giving admins on those plans time to review it first.

Mechanically, auto mode replaces most permission prompts with a classifier, a small AI check that looks at each action before it runs and blocks risky ones. When it blocks something, Claude usually finds a safer way to do the same task, or asks you directly. If it keeps hitting blocks, three in a row, or twenty across one session, it falls back to asking for manual approval again. Anthropic is also dropping the extra charge for running that classifier on Pro, Max, and Team plans, effective today.

The reason Anthropic gives for making this the default is that people were not really reviewing the prompts anyway. Its own data shows users approve 97% of permission prompts, which reads less like careful review and more like reflexive clicking. People do push back on other kinds of AI decisions: when Claude proposes a plan for approval, users reject it 39% of the time. But for individual permission requests in the middle of a task, the rejection rate drops to just 3%. As of June 2026, 49.5% of active users had manually created a rule that lets certain commands run without asking, called a Bash allow-rule; 5% allow any shell command outright, and another 43% have rules like Bash(python:*) that are close to the same thing in practice. That share is growing roughly 5 percentage points every five weeks, and 62% of users have at some point clicked don't ask again for shell commands entirely.

To test whether the classifier actually catches more than a human would, Anthropic ran a study with 1,053 paid testers. Partway through each session, one routine permission prompt was swapped for a clearly dangerous command. The testers caught the dangerous command just 13.6% of the time (143 of 1,053), while auto mode blocked 89% of the same commands (937 of 1,053).

The upside Anthropic points to is speed: unblocked from constant prompts, Claude can work on its own for longer stretches, which matters more with slower, more capable models like Opus 5 that are meant to run for hours. Among its Teams and Enterprise customers already using auto mode, including Adobe, Nuro, Gusto, and Garner Health, adopters ship about 25% more pull requests, proposed code changes, than those still on manual approval.

The testers caught the dangerous command just 13.6% of the time (143 of 1,053), while auto mode blocked 89% of the same commands (937 of 1,053).
via Claude →
02 Key News

Anthropic adds invisible AI marks to Claude's text and images

Anthropic said Claude will start hiding invisible marks inside the text and images it generates, so an automated checker can later confirm Claude made them. This lands on your desk because you publish AI-assisted writing on Exploded View and elsewhere, and this changes how that work can be tagged going forward, even after you have rewritten most of it yourself.

The trigger is the EU AI Act, Europe's law requiring AI companies to build ways of spotting AI-generated content. Anthropic is not limiting the change to Europe though: it is rolling the mark out worldwide, and into specific products too, including Claude Code, its coding tool. The move also lands amid a wider complaint that the internet is filling up with low-quality AI content, sometimes called "AI slop," so Anthropic is framing this partly as a quality signal, not just a rule it has to follow.

Image watermarking already works this way across the industry and is the simpler half of the change: a set of clues gets embedded in the picture file, invisible to a person looking at it but readable by a detector built for the purpose. Anthropic warns this has a real gap: the mark can be stripped out if someone converts the image to a different format or just takes a screenshot of it.

The bigger and more controversial change is doing the same thing to plain text, something Anthropic calls the "Claude mark." The company has not explained exactly how it works, likely in part so people cannot easily find a way to strip it. Anthropic says the mark will not change the meaning, quality, or readability of what Claude writes.

Here is the catch that has users worried: if you ask Claude to edit a paragraph you wrote yourself, the result can still carry the mark, because the mark reflects that Claude touched the text, not who came up with the ideas. Anthropic said it directly: "A detected mark provides a signal that content was processed by Claude, but is not fully conclusive." It added that a mark "does not, on its own, confirm the full provenance of the content," meaning a detector cannot tell you whether the ideas were yours or Claude's, only that Claude was involved somewhere. The reverse is also true. No detected mark does not prove a text is human written. It might come from a Claude model released before the mark existed, get heavily edited afterward, or simply be too short to carry a reliable signal.

Rollout is narrow for now: only text and images from Claude models released after 2 August 2026 carry the mark. Worth watching: how confidently people treat a "may have been processed by Claude" signal once tools built on this show up in plagiarism checkers, school software, and publishing platforms. A probability has a way of getting read as a certainty once it is embedded in someone else's product.

via The Independent →

OpenAI expands ChatGPT ads to five more countries

OpenAI has been quietly building ads into ChatGPT since February 2026, and as of this week the ad-supported version is live in five more countries: the UK, Mexico, Brazil, Japan, and South Korea, with more markets promised before the end of the year. This is worth tracking because OpenAI is the company you measure Claude against, and this is its clearest answer yet to how a chatbot company pays its bills at hundreds of millions of users.

The test started narrow. On 9 February 2026, OpenAI began showing ads only to logged-in adult users on the Free tier and a low-cost "Go" tier, in the US. Anyone paying for Plus, Pro, Business, Enterprise, or Education sees no ads at all. On the Free tier you can also opt out of ads entirely, but the tradeoff is fewer free messages per day. OpenAI's stated goal is to pay for the chips and infrastructure that keep the free product running, using ads instead of raising the price of entry.

In March, OpenAI said its ads pilot was "focused on supporting broader access to ChatGPT while preserving consumer trust, usefulness, and user control," and widened the test to Canada, Australia, and New Zealand. In May it announced plans to add the UK, Mexico, Brazil, Japan, and South Korea. As of this week's update, that expansion has now actually gone live in all five of those countries, and OpenAI says more markets are coming this year.

Every ad is kept visually separate from ChatGPT's actual answer, and OpenAI states plainly that ads do not influence what the answer itself says.

OpenAI says its focus with this test is learning, before it commits to bigger ad formats or opens the advertiser program more broadly.

via OpenAI →

House Democrats want AI companies to testify on recent hacks

House Democrats in the US Congress are calling on AI companies to testify about a string of recent hacks, calling the incidents a "clear risk to safety," according to CNBC. No further detail on which hacks or which companies are named is available yet. Regulatory pressure on AI companies keeps building, which matters directly for the tools you rely on every day, including Claude.

via CNBC →

Bitcoin miner Riot Platforms signs a deal with Anthropic

Bitcoin miner Riot Platforms has signed a deal with Anthropic, according to CNBC, another sign that crypto mining firms are repurposing their power and hardware for AI computing instead. It shows where AI infrastructure demand is pulling capital and electricity next: out of crypto mining and into running AI models.

via CNBC →

China releases free AI tool to screen rare diseases

Outside your usual reading: Chinese researchers at BGI-Research released OneGenome, a free AI tool for reading raw DNA, with the model itself made public so anyone can run it, aimed at diagnosing rare genetic diseases faster. The team says it beat general AI models like DeepSeek-v4 in clinical diagnostic tests, a rare case of AI given away free for direct medical benefit rather than kept behind a paywall.

via South China Morning Post →

Musk's $16.8 billion Texas chip factory would dwarf any building

SpaceX and Tesla are building Terafab, a $16.8 billion, 100 million square foot chip factory in Grimes County, Texas, more than five times the size of the world's current largest building. The project is designed to produce more than 1 terawatt of compute annually, a sign of how big the physical bet on AI chips has grown.

via reddit r/ArtificialInteligence →
03 Insights

Compression and next-word prediction are the same math problem

A technical essay argues predicting the next word and compressing a file are the same underlying task.

A Hacker News-favorite engineering essay makes a claim worth sitting with: compressing a file and running a language model, the kind of AI behind Claude and ChatGPT, are underneath the same math problem. That is a sharper way to think about what Claude is actually doing every time it predicts the next word, and it is useful the next time you are deciding how much to trust a model's output or why a smaller, cheaper model can still be surprisingly good.

The essay separates two things people often confuse. Minification, the trick of shrinking code by stripping whitespace and shortening variable names, only removes what a machine does not strictly need. Real compression instead exploits redundancy: repeated patterns in the data. Take a string of 9 A's, 4 B's, 2 C's, 1 D, 3 A's, then 9 D's. Written the normal way that is 28 characters, 224 bits (8 bits per character). Rewrite it as runs instead, "A9B4C2D1A3D9," and it drops to 12 characters, 96 bits: 57 percent smaller, just by noting how many times each symbol repeats in a row.

The essay names three parts every modern compressor is built from. Transforms reshape data to make it more compressible, run-length encoding above is one example. Models describe the shape of the data: count each letter across the whole string (12 A's, 10 D's, 4 B's, 2 C's out of 28) and you get a probability for each symbol showing up: A 0.429, D 0.357, B 0.143, C 0.071. Entropy coders take those probabilities and actually produce the compressed file, a raw stream of bits.

The essay picks one entropy coder, arithmetic coding, to show why better probabilities directly mean smaller files. Take the string "A B A B A A C," seven characters: 4 A's, 2 B's, 1 C. Turn those counts into a range from 0 to 1, split by probability: A gets 0 to 0.571, B gets 0.571 to 0.857, C gets 0.857 to 1. Walk through the string one symbol at a time, and each time shrink the current range down to just the slice that symbol owns, using the same probabilities again inside the new, smaller range. After all seven symbols, the whole string has been squeezed into one tiny numeric range: 0.38730 to 0.38855. Any single number inside that range can now stand in for the entire original string, because reversing the same steps regenerates it exactly.

That is the piece worth carrying into how you think about Claude. The "model" stage of a compressor is doing exactly what a language model does when it predicts the next word: assigning a probability to every possible next symbol given what came before. The better those probabilities match reality, the fewer bits an entropy coder needs to represent the actual outcome. The better a language model's next-word guesses match what a human would actually write, the more of the real pattern in language it has learned rather than just memorized. Prediction accuracy and compression ratio are, in a real mathematical sense, the same score measured two ways. That is the essay's title, and the mechanics above back it up: a model that compresses language well is, by construction, a model that predicts it well.

Worth flagging: the version of this essay pulled for you cuts off mid-explanation, right as it starts discussing how to pick the best number inside that final range. The mechanics above are solid and drawn directly from the piece, but its closing argument tying this back to how today's language models are trained is not in what was captured, so treat that connection as the essay's framing, not a fact confirmed here. Worth opening the original if the idea sticks with you.

I was reading about compression recently when I stumbled upon something crazy: that compressors and LLMs are, at their core, trying to solve the exact same problem.
via ngrok blog →
04 Tools & Craft

Mojo hits a stable 1.0 release after three years

The AI-focused language now promises not to keep changing under you.

If you ever pick a language to build AI systems on, this is the kind of update that matters: Mojo, the programming language built for AI work, just reached its first stable 1.0 release, and its maker is promising the language will not keep shifting under you the way it has for the past three years.

Mojo comes from a company called Modular, and it first shipped in 2023. Since then the team changed the language quickly and often, which made it hard for outside developers to build anything that would last. Modular says that era is now over: Mojo has grown into a general-purpose language with a real outside community, and Modular itself runs the language in production as the foundation of its own commercial products, MAX and Modular Cloud. Since Modular made the standard library's code public, nearly 200 outside contributors have landed more than 1,100 pull requests (proposed code changes), changed over 200,000 lines of code between them, and more than a thousand other people have filed issues that shaped the language.

The promise behind 1.0 is stability. During this 1.x period, changes should mostly add new things rather than break old code, giving developers confidence the language will not keep shifting under them. This release also finished a long round of language simplification and cleanup aimed at that goal.

Alongside that cleanup, Mojo 1.0 adds real new capability. It now supports Python-style lambda syntax for writing small inline functions quickly. The Mojo AI Skills, Modular's guided walkthroughs for tasks like starting a new project, programming GPUs (the chips that run most AI models), and porting code over from other languages, are now considered 1.0 ready.

Alongside Mojo, Modular's MAX platform, its system for running AI models, picked up support for two new model families this release: GLM-5.2 and Nemotron-H.

Getting started takes two commands: uv pip install --upgrade mojo, then uv pip install max[all]. Modular says it will share more about where Mojo and MAX go from here at its ModCon event in San Francisco on August 18.

Mojo 1.0 is a major milestone, but there's so much more we are planning for the language.
via Modular →

A Reddit joke names the real Enter-key anxiety of AI coding

A Reddit post captures the small daily friction of switching between AI tools.

Outside your usual reading: a Reddit post that turns a real, small annoyance into a joke anyone doing AI-assisted coding will recognize.

Posted to r/ArtificialInteligence, it describes what the poster calls EKAS, Enter Keypress Anxiety Syndrome. Before AI tools, pressing Enter was automatic. Now, with more than 15 keyboards' worth of habit undone, every keypress needs a decision: is this the web chat window or Claude Code? Plain Enter or Shift-Enter? Some setups even have Control-Enter wired to send instead. Guess wrong and you risk sending a half-finished prompt, wasting the tokens, chunks of text roughly three quarters of a word each, the model would have spent answering it properly.

The post is a joke, but the friction it names is real: different AI tools bind the same keys to different actions, and there is no shared standard across them. The poster's proposed fix is also a joke, a new keyboard key called NEMP, short for Now eat my prompt, meant to settle the question once and for all. No such key is coming. The honest fix is smaller: check which key actually sends in each tool you use regularly, and stop trusting muscle memory to know.

Cognitive load seems to have at least quintupled when it comes to using my Enter key(s)!
via Reddit r/ArtificialInteligence →

Nvidia's smaller Nemotron model routes AI agent tasks automatically

Nvidia added Nemotron 3.5 Lightning, a 30-billion-parameter model built from many smaller specialist models, aimed at AI agents that run continuously. It claims up to 4 times faster answers and 30% faster task completion than similar models. Nvidia also released NeMo Switchyard, a free tool that automatically sends each step of an agent's work to whichever model handles it best, cutting cost without a rewrite of the application.

via NVIDIA Blog →
The Last Word
The software starts acting on its own, and now it signs its work.
The Desk Report

How this edition came together — from bookmarks and feeds to the page.

222links gathered
40read by the desk
11made the edition

Where they came from

On the cutting-room floor — 29 links read but not run this week

Quality over volume: most links get a second look and a pass. The ones that made it earned their place.

Reading Room — every Sunday

The week's AI signal in 16 minutes — what happened, why it matters, and what to do with it. Curated by someone who actually builds, not a feed algorithm.