All posts by Davi Ottenheimer

Dobrindt Must Resign: CSD Terrorist Was Well Known and Attack Preventable

Deutsch | English

National Security Brief –>

People leaving the 48th Christopher Street Day on 25 July 2026, around 22:00, were attacked by a white van that entered the Great Animal Hunting Garden (Großer Tiergarten) in Berlin and drove deep into the middle of the park along a pedestrian path, the Ahornsteig, near Lennéstraße by Potsdamer Platz, striking people along it before crashing into a tree. One woman died at the scene.

The white Citroën van against the tree where its run down the Ahornsteig ended.

The joint release of Polizei Berlin and the Generalstaatsanwaltschaft records further injuries from the vehicle and from stabbing tools. There is still disagreement on the harms: Bundesinnenminister Alexander Dobrindt said twenty-nine injured, the fire service itemized three life-threatening, eight severe and five light. Scene photographs show a white Citroën van-bodied passenger vehicle with Berlin plates, a Pkw by registration and a Transporter by body; police call it a private vehicle against early reports of a rental. It was abandoned at the scene, the suspect on the run with a stabbing weapon after striking at people on foot, his phone left behind in the van. Overnight police arrested a second man they describe as his suspected passenger.

Berlin digital billboard displaying police wanted poster.

On Sunday around 18:00 a police special unit located Abdul Ballout in a Spandau allotment colony; police say he ran at officers with a stabbing weapon and was shot dead.

The location of the attack is clear. The van drove deep into the park on a wide path, outside the demonstration area, after the demonstration had ended while the crowd was still reveling in the night. 22:00 after CSD official events means near peak density for the night festivities.

Middle of Berlin’s very large Tiergarten, where a large white van drove in a terror attack.

CSD Berlin is a registered assembly. Berliner CSD e.V. files it annually under Article 8 of the Grundgesetz, and Berlin assigns assembly protection to its police. Brokdorf (BVerfG, 1 BvR 233/81) obliges the state to shield an assembly against external attack.

The CSD event area itself sat inside a police barrier concept under Polizeipräsidentin Barbara Slowik Meisel, and that concept held. The attacker use of the Ahornsteig lies outside it, a Grünanlage path maintained by the Straßen- und Grünflächenamt of Bezirksamt Mitte in the Geschäftsbereich of Stadtrat Christopher Schriner. The office responsible for the park sits at Straße des 17. Juni 31, inside the park. Its trucks use the paths. The entrances the attacker exploited are built for maintenance, and apparently unguarded despite the high risk for the kind of attack Germany has become known for failing to prevent.

The responsibility for the entrance vulnerability was established on 11 December 2025. The Senatsverwaltung für Inneres und Sport answered Schriftliche Anfrage 19/24467 on vehicle barriers at Christmas markets, the same threat class as CSD. Asked whether Zufahrtsschutz belongs to counterterrorism, to general Gefahrenabwehr, or to an organizer’s civil duty of care, Senator Iris Spranger’s administration answered over the signature of Staatssekretär Christian Hochgrebe:

Eine von den Umständen des jeweiligen Einzelfalls losgelöste allgemeingültige Abgrenzung ist nicht möglich.

EN: It is not possible to draw a generally valid distinction that is independent of the circumstances of each individual case.

The document lays out divisions of responsibility. Organizers of private events carry the civil Verkehrssicherungspflicht for the event ground. Everything beyond falls to the Bezirksamt as Ordnungsbehörde. The police advise, decide nothing, and bear, in the Senate’s words, neither competence nor obligation to erect vehicle barriers at private events, reserving only emergency action and case-by-case exception.

The same five pages date the controlling judgment (OVG 11 B 6.19) to two different dates: 6 August 2020 in the questioners’ quoted preamble, 15 June 2022 in the Senate’s answer to question six. The discrepancy went to print unreconciled. For assemblies the organizer’s share falls away entirely, because assembly law forbids charging protection costs to people exercising a constitutional right. Berlin’s Grünanlagengesetz, amended in 2024, ties park protection duties to Sondernutzung permits (GVBl. 2024 S. 475, § 6 Abs. 5 S. 2). A dispersing crowd holds no permit.

Ground Owner Instrument
Demonstration route and rally, for the duration Polizei Berlin Assembly law, police barrier concept
Event ground at private events Veranstalter Civil Verkehrssicherungspflicht
Everything beyond, including park paths Bezirksamt as Ordnungsbehörde General Gefahrenabwehr, Grünanlagengesetz
The doctrine Senatsverwaltung für Inneres und Sport Drucksache 19/24467: case by case only

The deployment on the night of CSD then gets clarified by the police’s own statements. Spokesman Florian Nath told reporters that 214 Okta concrete blocks and 40 further Zufahrtsschutzelemente stood guarded around the entire Veranstaltungsgelände, the standard package, and that driving onto the event ground was not possible.

Onto the event ground. Note that detail.

He located the attack on the access paths between Lennéstraße and the Ahornsteig, near the event ground.

Near the event ground. Note that difference.

Regierender Bürgermeister Kai Wegner said the same: outside the secured area. Both statements are accurate, and together they explain a failure to protect people attending the event. The 254 elements enclosed the rally ground as formally defined. That defines the crowd at 22:00 on pedestrian paths deep inside a park as “outside” the event grounds, even though common sense would say it’s the most plausible place to be for CSD at that time.

Lennéstraße runs open along the park’s southern edge for half a kilometer, lined with entrances sized for maintenance trucks. The western edge is the former Entlastungsstraße roadbed over the B96 tunnel, a paved corridor open at both ends, and the Ahornsteig’s mouth opens off their junction. An eyewitness told AFP the van turned off Lennéstraße at speed; the police say the entry point is unidentified and the vehicle arrived unnoticed on partly unlit paths.

Asked how it got through, Nath answered: “Das fragen wir uns auch.” (EN: We ask ourselves the same thing.) No rule required the barriers to cover the space the crowd actually occupied, so nobody was responsible for checking whether they did. The standard measures protect moving onto the event ground and leave the crowds open to attack near the event ground, despite being deep inside a park where no vehicles should enter.

The escape of the driver also needs examination. He ran into a dark park filling with thousands who were also fleeing in every direction. The year’s largest police concentration was a few hundred meters away, facing inward. Earlier in the day the police had focused on heavy scrutiny of what the crowd was saying, yet with a terrorist on the loose the police suddenly went slack. There was no cordon to run into after a terror attack, because the ground he crossed sat inside nobody’s assignment. A ring around a fleeing man must exist to stop him, yet the police allegedly told everyone to leave, having the opposite effect and making it impossible to catch him. Thermal imaging over the Tiergarten and GSG 9 through Anhalter Bahnhof produced nothing for twenty hours. How the police found him, they have not yet explained; per a Bild report it was a tip from the attacker’s personal circle.

When police ended the CSD the crowd was sent out of the barriers and onto streets and unprotected paths. The van was dead against a tree. The driver had stepped from the wreck with a stabbing weapon, struck at people on foot, and vanished into the dark, and whether a second attacker moved in the crowd was, at that hour, unknown. The decision to disperse faced genuine uncertainty. Dispersal without a filter answered it badly.

Flushing a sector and filtering it are incompatible without a filter, and the outflow ran without checkpoints. Tens of thousands streamed across exactly the class of ground where the attack had just occurred, and the flow that carried them out carried the attacker with it. Holding the hardened ground against emptying it was a judgment call under pressure; a filter on the exits was a plan that had to exist beforehand, and it was absent from the concept the way the Ahornsteig was absent from the barrier map. Why the call was made, and against what alternatives, the police have yet to explain. An attack aimed at an assembly, that ends the assembly, obtains its object.

Earlier in the day, a stark contrast is worth considering. A few kilometers north, at the Internationalist Queer Pride, police monitored very closely every move and word in a march of 7,000 and made nine arrests, most for propaganda offenses tied to the “river-to-the-sea” chant; a year earlier the force put about 1,300 officers on the 10,000-person version. Slogan enforcement has a statute, a court-maintained standard, assigned listeners, and a measured output by morning. The full stack of instant threat assessment exists for words. For a giant white van driving through a park at night, two tons of moving mass at the edge of the largest gathering of the year, the police appeared unprepared and unaware of how to protect the public.

The gap follows from two planning methods. Since the Love Parade deaths in Duisburg, German event planning models crowd flow so that people can leave fast and spread wide. On the other hand, barrier planning follows the permit process for the event and the event schedule. The unprotected area is the difference between the human movement model and the formality of a space permit, and it is largest during departure, when egress design spreads people across many routes at the moment the barrier plan stands down. Currently no German planning document reconciles the difference between reality and bureaucracy.

The same boundary failure has been repeating in successive configurations.

Date Site Boundary that failed
19 Dec 2016 Berlin, Breitscheidplatz Market flank without barriers
7 Apr 2018 Münster, Kiepenkerl terrace Permanent public space, no event boundary existed
1 Dec 2020 Trier, pedestrian zone Permanent public space
20 Dec 2024 Magdeburg, Christmas market Gap kept open for rescue vehicles inside the barrier plan
13 Feb 2025 Munich, ver.di march Moving assembly, perimeter existed only where the march stood
3 Mar 2025 Mannheim, Paradeplatz Permanent public space
25 Jul 2026 Berlin, Großer Tiergarten Departure area beyond the assembly boundary, after the assembly ended

In three of the seven cases the driver already sat in state threat files, Breitscheidplatz, Magdeburg, the Tiergarten, and in each the file changed nothing. The other four had at most ordinary police contact, which is the impulsive-attacker profile prediction cannot reach.

The Breitscheidplatz driver was a registered Gefährder under observation.

The Magdeburg driver had years of warnings on file.

When Ballout attacked CSD he already was polizeibekannt, and his file, like Amri’s, had been handled in the Gemeinsames Terrorismusabwehrzentrum, most recently in its working group for the highest-risk cases.

The surveillance argument says increasing more and more knowledge enables interception: detect, decide, interdict, chain complete before contact. Surveillance ran at maximum on Ballout and delivered zero interdiction. The chain broke at its final link, and expanding the first link repairs nothing.

A two-ton van among pedestrians is visible to any camera and any bystander, and here the condition was not an instant but a duration, sustained driving through the park interior, deep among people walking home, the violation in continuous existence for the length of the run. If you can’t identify a giant white van speeding through a park immediately, then expanding detailed surveillance with highly sophisticated markers makes no sense at all.

No one was assigned to watch the park at 22:00, because the 254 elements watched the polygon’s edge and the park interior was on the other side, in a park that should not have had cars inside at night. This is not a time for scoring and inference, because the answer is simple. Vehicles do not belong in crowd space, rescue and maintenance being known exceptions, everything else is denied. The infamous plain white van that would fail every allow list is not a generic object awaiting assessment. It is the hazard itself, the object the term Überfahrtat was coined for.

Stopping two tons at fourteen meters per second takes counter-mass (barriers) placed in advance; no dispatch is fast enough. German law already knows this and takes kinetic energy seriously: machine-safety law requires guards between moving mass and bodies, and the Eisenbahnkreuzungsgesetz mandates separation where rail crosses road, with costs divided by statute (§ 13 EKrG). Nobody proposes to solve railroad-crossing deaths with better locomotive driver registration and detailed monitoring.

If the security test collapses on the most visible object under the simplest rule, the argument for finer inputs and more expensive surveillance will repair nothing. A face at fifty meters or a phone location is a weaker signal than a white van approaching a crowd, and it feeds the same missing step.

The math also proves this point. There are fifty million registered cars in Germany, single-digit attackers per year, so individual prediction floods its operators with false alarms while the class rule misses no vehicle attacker by definition. The rule owns the mass-casualty vector. The blade phase that followed the crash belongs to police response, and the van did the mass harm.

And prediction assumes the wrong attacker, a plotter who emits signals over weeks. Münster’s investigators pointed to documented psychological problems; Trier’s trial turned on the driver’s mental state; Ballout left his phone in the crashed van, hid twenty hours in a garden hut, and ran at armed police with a knife.

The record so far shows no tradecraft to pierce with intelligence operatives and no planning beyond the obvious indicators the Germans already had for Ballout. He was impulsive. He wanted to commit a terror act and join a terror group. An impulsive attacker means prediction gets lost in bureaucracy, while a barrier to highly likely and highly severe attacks prevents it by design.

Perhaps more to the point, the high-cost unpopular prediction platform also justifies its own expansion with every miss. The less it works the more it claims to need an erosion of opposition. However, the simple perimeter concept ends the problem and the spending together. In every listed case the risk signal converted into a report. It did not result in better perimeters or physical control, because that required an agency that owns the ground to deploy and maintain it on. No such agency seems to exist for the space the CSD terrorist attacked.

That is the standard a federal response requires, and the hook sits in federal law. Article 73 Absatz 1 Nummer 9a of the Grundgesetz hands the Bund defense against the dangers of international terrorism through the BKA, the BKAG carries it into statute, and the GTAZ that circulated Ballout’s file sits under the Bundesinnenministerium. Dobrindt claimed the ground himself when he announced a review of security concepts the day after the attack. A minister who claims the review claims the standard. His ministry’s legislative output this term consists of identification and analysis powers: the Sicherheitspaket drafts for automated biometric matching and merged analysis platforms, a federal Palantir deployment under review, and in January a push to soften the EU AI Act guidelines constraining exactly these systems.

That’s right. Palantir, the infamously fascist company with extremist founders whose German police deployments already produced a Bundesverfassungsgericht ruling striking down their legal basis (1 BvR 1547/19, 16 February 2023). Dobrindt has been talking about removing legal safeguards on surveillance while partnering with fascists, which of course won’t turn out well, while the absence of physical safeguards on the ground of course hasn’t turned out well already.

Nothing in the ministry’s output says he will get any better at keeping a vehicle away from a crowd, despite that being the known and repeating threat vector.

Either the agencies lack the mandate to enforce a crowd perimeter, which is the law the Drucksache describes, and the failure belongs to the ministers and legislators who left it unwritten through nine years and seven attacks. Or the mandate lives in the discretion the agencies already use, the 254 barrier sections prove the capability, and the failure is that nobody is measured on coverage, because a voluntary measure has no target to miss.

Not empowered, or not measured. Both are a failure of Dobrindt’s leadership.

Both belong to the offices now announcing reviews, and the exposure continues. Who is the owner of the paths off Lennéstraße, in terms of a terror attack on tens of thousands of people in the middle of a park? After the suspect’s death, Dobrindt said on ARD that authorities assume no further danger, adding in the same breath: “Aber das ist alles immer eher eine Momentaufnahme.” (EN: But all of this is always more of a snapshot.) That assessment refers to the suspect being killed. But the condition that admitted his vehicle, like all the vehicular attacks before his, seems to sit unchanged in Dobrindt’s speeches.

That declaration of no further danger needs a basis, and a snapshot concedes it has none. A minister who declares the public safe without a standard to measure safety against is not reporting a condition. He is manufacturing one to an unaccountable level. The blame that Dobrindt has assigned is also on the record: in the ARD interview he said he’s focused on how a Gefährder can receive a suspended sentence. He didn’t mention how a giant van can drive through the middle of a pedestrian path in a park. Wegner aimed at the wrong target too with “mir fehlen da schon die Worte,” (loss for words) with references to custody, deportation detention and preventive detention plus IP retention and surveillance law.

Let me be clear here, because these are political statements detached from all reality. Deportation detention has nothing to do with a citizen born in Berlin. Surveillance of the German man could not have been more available or higher. He already was known and tracked, which proves the surveillance isn’t the fix.

Sure, they say they would have put Ballout in a cell, but the problem is still that the Ahornsteig entrance is open for the next driver, one of fifty million, whether they are under full surveillance or not. Huge crowds no longer subjected to vehicular threats is the lowest cost fix for the absolute highest safety gain.

The targeting talk also diverges from what was known using surveillance. The FBI warned publicly in 2024 of attacks on Pride events. Any head of safety with basic competence levels would have anticipated this exact threat as high or highest probability.

In May 2025 the Gelsenkirchen CSD was called off minutes before start over a threat the LKA judged serious; in February 2026 the Islamist motive was confirmed. The protective control was cancellation, serving the attackers. The BKA ledger lists 420 Islamist Gefährder, and Ballout was among them at the GTAZ’s top tier.

So if the surveillance target class already was named in advance, and the exact individual was named in advance, what would any more surveillance achieve? Nothing. If Sunday’s safety declaration is valid, the capability behind it ran before Saturday and delivered exactly zero protection against the van driving through the park.

In other words, the failure proves the why and how safety leadership has to change. Look back now at how the IMK put the subject on its agenda in June 2018, TOP 19 of its 208th session, Schutz öffentlicher Räume vor Überfahrtaten, and a joint Bund-Länder working group was established that August. Over six years it produced two DIN SPEC standards, a handbook, a planner qualification catalog, and a KfW financing option. Every instrument was voluntary, with no duty assigned, and no coverage required. The prevention literature of Bund and Länder names Grünanlagen explicitly. And then what happened?

By 2024 the programme literature reported the group’s work complete and its dissolution put forward; whether the IMK formally dissolved it is not in the published record, which releases only a subset of decisions.

Magdeburg followed within months, then Munich, Mannheim, the Tiergarten. All of it preventable.

The first regular IMK after those three, 82 items in June 2025 with Dobrindt attending for the first time, released decisions on drones, knives, civil defense and identity management, and no duty on the ground.

Under Article 65 of the Grundgesetz the minister answers for his portfolio. A conviction for his failures apparently rests on three counts.

Count one, the escalation. Ballout escalated through every stage the state records, violent offenses, IS sympathy, the Syria attempt, the § 89a conviction, the Gefährder classification, the GTAZ’s highest-risk tier, counselors who found him inscrutable, a search three weeks out, and the minister’s fourteen months in office added watching capacity and no converting capacity.

Count two, the attack. His level studied ground protection for six years, produced voluntary standards, declared the work finished, and released nothing after three further attacks put the question back. The attack that followed required one unstable man, one van, and one open park entrance, the most basic entry level of the discipline whose leadership he claims. On a similar note, he was publicly ridiculed after he claimed “left-wing” threats were increasing from 11,200 to 11,200. That wasn’t a typo or an accident, as he also tried to dismiss the actual rise in “right-wing” threats. The actual numbers were being made irrelevant to his unmoored, political beliefs.

Count three, the aftermath. He certified safety without a measure, aimed the inquiry at a court whose reversal would have protected nobody but the instance, announced a review of his own portfolio, and did not once name the entrance, the mandate, or the coverage. His record on consequence is documented: the Pkw-Maut he designed was ruled unlawful by the European Court of Justice, causing a 243 million euro settlement, which he dumped on his successor. Somehow his failures have allowed him to rise up instead of being accountable. A review he commissions of a failure he presided over is not independent enough to be trusted.

Germany treats the prosecution of such an attack as federal and its prevention as local. The Generalbundesanwaltschaft took over the investigation within a day, while the question of who guards the ground stayed where it fell. Per the Generalstaatsanwaltschaft, Ballout was a German citizen born in Berlin, arrested at BER in late 2025 returning from an attempt to reach the Islamic State, sentenced by the Amtsgericht Tiergarten on 12 May 2026 to one year and ten months of Jugendstrafe with remand credited, and released with the judgment under appeal, against the prosecution, which had sought a non-suspendable sentence and continued custody. Counselors reportedly found him inscrutable and claimed he posed no acute threat; his third session with them was set for the Monday after the attack. The credibility of Berlin’s professional threat assessors does come into question.

The sentencing court and appeal chamber are the independent Berlin judiciary, Gefährder monitoring runs through the Berlin LKA, the counseling program is a Land instrument, and the GTAZ, where the BKA sits under the Bundesinnenministerium, coordinates and decides nothing. The custody chain deserves its inquiry, however fixing it fixes a case, if not the institutional failure. With Ballout dead, criminal proceedings against him end and the Generalbundesanwaltschaft carries what remains, including the case of the suspected passenger; examination of the officials who held the protection question isn’t likely to come from a federal-level review of themselves.

The better analysis is that every large gathering files an Abströmanalyse, modeled crowd density over space and time from arrival until dispersal below a threshold, using the simulation practice already standard for evacuation planning. Protection attaches to the modeled crowd, because it’s discrete and well known how to do it effectively. Every vehicle access point in open pedestrian areas enters a register with a closure state and a named owner; open edges where a vehicle can leave the road are closed as lines, by curb, ditch or barrier; rescue access is a staffed gate, the lesson of Magdeburg’s unsupervised gap. An auditor checks one thing: no part of the modeled crowd area outside the protected area. The audit stays internal.

The fix is an assignment to a level of authority that oversees the whole crowd. The Länder extend the police protection duty through the departure phase, until modeled density falls below threshold. Brokdorf grounds the duty in the assembly itself, and safe dispersal is part of the assembly; the extension writes into statute what the judgment already implies, which makes 25 July read as breach of an existing constitutional duty rather than a gap awaiting a law. For events and permanent pedestrian areas, Germany adopts the structure the United Kingdom enacted on 3 April 2025 in the Terrorism (Protection of Premises) Act, a legal duty, one named duty holder per site, a regulator, with one correction: the UK law leaves open public space uncovered, and the German record concentrates there. One named authority per Land, districts implementing, costs divided by fixed statutory formula on the § 13 EKrG model. The equipment is ordinary: certified removable barriers, closed by default on days the police event calendar lists a large gathering, under standing agreements, so that closing them requires no new decision by anyone.

Bottom line, is the state knew the threat actor and had been watching him in great detail for a long time. And the state surveillance didn’t mean a thing when the hallmark vehicle attack on a crowd became an impulse in Berlin at 22:00 on a Saturday.

Three weeks before the attack he posted a photo of himself with a gun. Police pounced, searched his home, found a toy pistol, and then closed the case. Surveillance at work. Then he got into a van and drove it into a crowd. That weapon was allowed near the crowd by default, because unclear reasons. That is the real finding, yet again.

Surveillance mattered little to not at all, because the weapon was not only allowed it was ignored. How did he drive so far into the park, and so easily walk away, given the huge police presence? The announced federal review is completely inverted from what matters in the case. The threat is not from masterminds who justify precision intelligence tools to decipher. It is from anyone in a bad enough state to drive into people, a population that would forever be ahead of any surveillance capability. The perimeter to stop vehicles, when designed right, is infinitely faster than any surveillance system. Until the law names a responsible agency and requires that proper perimeter, the German leadership simply enables the same attack again.

History Professor Catches AI in Class: Madagascar purple bicycle whispers to the ceiling

In radiology a patient swallows barium sulfate to make the invisible digestive tract show up on X-ray. Counterintelligence uses this method, sending something traceable into an closed system to record its appearance. And so the method has been described as a “barium meal” (PDF).

Hank Prunckun, Counterintelligence Theory and Practice, 2019, pg 195

For example, when you give different suspects slightly different versions of a secret, the version that leaks will identify the mole. Peter Wright in 1987 wrote Spycatcher about MI5 using the method. Imagine if Snowden had released seeded data, instead of dumping everything, since he didn’t read or understand anything he was doing.

I guess you could say Snowden was ahead of his time, because now the vast majority of students in a history class behave like him.

…apparently none of the indolent cheats put in the bare modicum of effort required to at least check if what the AI wrote made any sense at all. All they did was copy-paste the midterm instructions into a chatbot, then copy-paste the chatbot’s spiel back into the answer window.

That sounds exactly like Snowden to me. Copy-paste a crawler script into the system, copy-paste the dump into the Glenn Greenwald window. Snowden ran a mindless bulk collection with no reading pass, which begs the mole who played him as their mule. Who was the professor?

The version in this academic story compresses into a single step. Everyone got the same barium. The professor didn’t need to see different versions, just whether the meal passed at all. And then he published his results for journalists to pick it up themselves.

Jason Gibson, a history professor at Alcorn State University in Mississippi, says that he used white font to hide a prompt telling an AI model to spew nonsense in the instructions for his mid-term.

Unfortunately, it ended up working a little too well.

“Thirty-two of my 35 students between two classes failed a portion of their midterm because they all used AI to generate their entire response”

Consider how good this actually turned out for him. Historians are trained in detection of information integrity. They literally treat all input as untrusted and work hard to become trusted output generators. What the professor did is simply what historians always do in history tests, by forcing students to regulate output quality.

Gibson shared some of the most examples in a follow-up video. After introducing how AI and other technologies have impacted society, for instance, one midterm included this puzzling non sequitur: “Madagascar floats sideways through the afternoon.” (“Okay,” Gibson says, after a pause.)

Another droned on about something related to AI and social inequality, followed by: “Madagascar purple bicycle whispers to the ceiling.”

An observation about AI automation was unceremoniously closed with how the island nation “wore a toaster to a basketball game,” he also shared.

That’s what Snowden sounds like to me when he speaks. Purple bicycle whispers to the ceiling, click to subscribe.

The man who destabilized every institution he touched now asks the Kremlin for stability. The man who shed every obligation now wants papers proving he belongs.

I ran almost this exact test in 1993 when I was getting my history graduate degree, as I mentioned in my 2024 commencement speech.

When an LSE student repeatedly left their World War I essay about military vulnerability completely exposed on one of our four shared lab computers, the irony proved as irresistible as… relieving myself on a hidden electric fence back home. A risky temptation that I really should have resisted. After watching the pattern repeat daily with a stubborn predictability of the BBC weather forecast, I did what any country bumpkin would do facing an open barn door: I scattered pointed commentary about undefended positions throughout their work. Professor Stevenson, to my great relief, marked every single edit with a bright red circle, proving he dutifully read each word that we turned in — which is more than I could say for my fellow student about their own work.

Perhaps more to the point for historians working with AI safety, these students have another worry. The UK AI Security Institute reported on July 21 that “Every model we have tested for this behaviour attempted to cheat” on its offensive cyber evaluations.

One model, handed a task accidentally misconfigured to be impossible, wrote and ran code on an external internet service in an attempt to break into the evaluation infrastructure itself, triggering a security alert inside AISI.

Asked afterwards whether they had done anything suspicious, models named the behaviour inconsistently and called it wrong less than half the time. Some reasoned explicitly about whether an action counted as cheating, then did it anyway. I find this to be the very definition of “higher reasoning” in tech. If you want obedience, you limit the reasoning levels.

AISI’s conclusion is that self-report and chain-of-thought both fail as detection methods, which leaves seeding the environment and watching what passes through. That is the barium meal.

A history professor in Mississippi demonstrated more effectively what a fancy British government red team declared in the same week.

A system’s output can’t be trusted, so you can apply input controls to verify.

The History of Non-Conforming Women’s Work in the Middle Ages

Here’s an interesting history source, which brings to the screen Eileen Power’s Medieval Women, and which introduces some odd claims. For example, it says:

Most non-conformists became nuns

Well, that’s probably true for the gentry and nobility, and not the peasant majority. And it certainly wasn’t an option for the non-Christians. Ooops. Power wrote entirely of power (Christian Europe) as she probably considered Jewish and Muslim women as non-conforming, if she thought about them at all.

Consider the counter-example of Marguerite Porete, who wrote Mirouer des simples ames in the late thirteenth century, as found in Chapter 122, fifteenth-century manuscript, Chantilly, Musée Condé F XIV 26 (catalogue 157).

Amis, que diront beguines, et gens de religion,
Quant ilz orront l’excellence de vostre divine chançon?
Beguines dient que je erre, prestres, clers, et prescheurs,
Augustins, et carmes, et les freres mineurs,
Pour ce que j’escri de l’estre de l’affinee Amour.

Modern translation: My Love, what will the beguines say, and all the people of the church, when they hear how good your song is? The beguines already call me wrong. So do the priests, the scholars, the preachers, the Augustinians, the Carmelites, the Franciscans. All because I write about pure Love when nothing false is left in it.

Her book was burned at Valenciennes on the orders of the Bishop of Cambrai, who forbade her from circulating it by threatening judgment as a “relapsed heretic”. She circulated it anyway and was thrown into jail for a year and a half. She declined the inquisitor’s oath and never answered the tribunal, which condemned her for it on top of the book being circulated. The cleric Guiard de Cressonessart declared himself her defender and was punished with a sentence of life imprisonment. Three weeks after fifty-four Templars were burned at the stake, she was too on June 1, 1310 at the Place de Grève in Paris. Then her work circulated anonymously for six centuries in French, Latin, Italian, and Middle English, still copied and read to this day.

I guess the point here is that the film says a woman could choose marriage or a convent. Technically there was also the beguine, as a tolerated non-conformance. All of it reads as Christian. Jewish and Muslim women from birth were excluded by discrimination, their non-conformance forced upon them rather than chosen, since they couldn’t be in a convent or beguinage. Porete is the story of a woman who chose another path and was murdered for it. She didn’t even conform to the non-conformance.

Musk Counterfeits Open Source and NVidia Posts a 25 Company Letter to Help

I was asked to give my opinion on a new tech policy letter published by twenty-five organizations, titled Open Weights and American AI Leadership.

Nvidia published the PDF, and Microsoft mirrored it to its corporate responsibility site. Jensen Huang very strangely joined a social media platform based on a Nazi Swastika last month, and then spent his first post ever promoting it.

This artist’s rendering of the X brand was deleted from the platform by the self-promoting “free speech extremist” Elon Musk. Source: Ai Wei Wei

The tech policy letter promoted with a Swastika asks Washington not to restrict downloadable AI models. It declares openness a foundation of AI safety:

[Open models] allow a broad community of researchers and developers to examine their behavior, identify vulnerabilities, develop safeguards, and improve them over time.

Eight days earlier, the prominent open sourcing announcement by the infamously Hitler-saluting Elon Musk demonstrated that he’s playing games with language as usual.

Like a (supervised) full self driverless car that isn’t driverless, guess whose “open source” propaganda is the opposite act? Do you ever get the impression that he just lies and doesn’t care that millions of people will die because of him (14 million projected by 2030)?

Herr Elon, your laundered open source isn’t open source

On July 12, a researcher publishing as cereblab released a wire-level analysis of Grok Build, the terminal coding agent from xAI. The method used was ordinary interception: version 0.2.93 of the client routed through mitmproxy, with the full captures published.

The findings were like seeing a Tesla on fire.

Teslas notoriously “veer” uncontrollably and crash. Design defects (e.g. Pinto doors) trap occupants and burn them to death as horrified witnesses and emergency responders watch helplessly. Source: VoCoFM, Korea, 2024

Grok Build was secretly packaging users’ entire tracked Git repositories, full commit history included, and uploading them as git bundles to a Google Cloud Storage bucket named grok-code-session-traces, where it was controlled by Musk’s xAI.

The numbers revealed that it was a codebase issue. On a 12 GB test repository of files the model never read, the model channel moved about 192 KB of task-relevant traffic while the storage channel moved 5.10 GiB, a ratio of roughly 27,800 to one. All 82 storage calls returned HTTP 200.

A canary credential planted in a .env file appeared verbatim and unredacted in the captured traffic. Let me say that again. The developer secrets were leaked by design, cleartext.

The researcher then cloned the captured bundle and recovered a file the agent had been explicitly instructed never to open. Users reported SSH keys, password databases, documents, and photographs leaving their machines.

The tool’s “Improve the model” toggle, the one control a developer would read as consent, had no effect on the upload. It was a dummy dashboard, just like the lies of a Tesla dashboard claiming 300 miles while the car tops out at 150 miles. The switch turned out to govern only training permission. The code was taken regardless of the setting. Tesla’s range deception ended the same way, with an August 2023 class action:

Tesla is facing a class-action lawsuit filed by customers who say they were misled by the company’s exaggerated range claims. The lawsuit was filed yesterday, days after a report revealed that Tesla exaggerated its electric vehicles’ range so much that many drivers thought their cars were broken.

The response to the Grok design failures was five steps. Each step is usually a simple and standard practice, which has verification. Instead, each was made incorrectly by xAI and to prevent verification.

The first fix was silent. A day after publication, the researcher retested the identical client and found a new server-side flag, disable_codebase_upload: true, now arriving with each session. The upload stopped. The flag was flipped remotely, announced nowhere, and verified on exactly one machine and one account. Whether it is global, staged, or permanent is unknown, because the mechanism that ended the collection is invisible by design. That’s the definition of closed.

Elon Musk then promised deletion of all data Grok Build had ever stored. Lol. This guy. He will say anything that he thinks people want to hear. Remember October 2016 when he said driverless would be completed for cross-country trips without touching the steering wheel by the end of 2017! Sure, sure Elon.

Source: My presentation at MindTheSec 2021

Deletion claims in cloud infrastructure are attestable. A named forensic firm, a published scope, deletion certificates covering replicas, backups, access logs, and derived artifacts including training data. Companies produce these documents routinely, because attestation is what anchors words to reality.

xAI produced… a post on X. In other words, nothing. A massive breach of confidentiality. The kind of design failure that should bring massive fines for negligence, ended with what?

The company disclosed no scope. The number of affected users, the duration of the collection, the volume received, whether the bundles were accessed or processed after arrival: every one of these figures sits in xAI’s logs. All were withheld. The wire captures establish what left users’ machines. And xAI has never admitted what that included.

On July 16, xAI published the Grok Build source code on GitHub under Apache 2.0, in Musk’s words to build trust in the product.

Musk declares Grok Build “open source” July 15, a day after wire captures proved it was secretly uploading users’ entire repositories. The repo he shipped has one commit and no history, a license without the evidence, which fails the entire stated purpose of open source.

With all the money in the world, the huge engineering teams and the American government eating from his hands, he produced … a repository with a single commit.

Zero pull requests. Zero history.

The one forensic question that matters is what the shipped binary did between launch and disclosure. He provided a repository without history. That’s basically a closed repository. It cannot answer any questions. The code as published shows what xAI wishes to be seen after the incident.

Whether the upload path was removed, renamed, or relocated to the server side is unknowable from the “proof” that appears as clean laundry. Git history is a chain of custody. This release destroyed the chain and presented the result as transparency. There is a bitter symmetry here. The company that harvested its users’ full git histories shipped its own repository without any history.

Get it?

Users’ private repositories, including code they never published anywhere, were pulled into xAI’s closed infrastructure without consent. Meanwhile xAI’s disclosure covered only the client. The server side that received the bundles, the storage bucket, the retention configuration, the access controls, the processing pipeline: all of it stays hidden, holding other people’s intellectual property, let alone all their secrets.

A failed apology isn’t the right word. This was a strategic play, a game to undermine trust while claiming to be providing it. A silent flag, deletion without attestation, disclosure without scope, code without history, openness without the server. There were five independent design decisions all delivered without anything that could be verified or held accountable. That’s closed behavior, unaccountability defined. At that point the failures stop being some trait or feature, and become the entire product itself.

Ok, ok, let’s talk about The Letter

The coalition letter treats “open” as a binary state. Flip the open switch, confer audit value automatically? That argument for safety depends on a single thread: openness enables verification, transparency anchors claims being made. The letter tells us:

Just as open-source software demonstrated that transparency can be more secure than obscurity, AI safety may depend on giving more people the ability to test and strengthen the models on which society relies.

It then goes on to name the outputs we should expect from openness: benchmarking, red teaming, vulnerability discovery. However, the letter forgets to mention that all of it depends on history, provenance, training data, reproducible evaluation, server-side scope. Those are the inputs, which Elon Musk proved he could completely destroy while claiming to be the “open” guy.

The reason I explained the Grok Build breach is because it proves the letter doesn’t work in the bed that Elon Musk is making for America. The release is open by every criterion the letter uses. Apache 2.0. Downloadable. Inspectable. Modifiable. The broad community of researchers can examine it. What the community cannot do is answer any question that matters, because every input to verification was stripped before publication.

If “open” is so easily gamed by people who want to humiliate the security property, then Grok Build is that proof. Grok Build demonstrably lacks critical security and can’t be trusted, because it can’t be verified. It’s the Tesla of coding. Therefore “open,” as the letter uses the word, is a label rather than a property, just like “driverless” isn’t. The letter’s central safety claim fails on a live case that predates its own publication by twelve days.

You can not tell me the signatories don’t know the difference, or don’t know exactly what Musk is doing by destroying the meaning of words. The rather uncomfortable timing is Musk suddenly claimed he was going to be “open” and then NVidia jumped on his Nazi Swastika platform to promote it with their letter promoting being “open”.

More importantly, Nvidia’s Nemotron 3 Ultra shipped in June with weights, post-trained checkpoints, training datasets including 173 billion tokens of refreshed code, and full training recipes under the Linux Foundation’s OpenMDW-1.1 license. That is disclosure of a normal company. Independent evaluators could score it, and did. Nvidia’s release practice draws exactly the line that matters: openness as an auditable property, versus a clown costume to undermine the meaning of openness.

A Nazi “Afrikaner Weerstandsbeweging” (AWB) member in 2010 South Africa (left) and a “MAGA” South African-born member in 2025 America (right). Source: The Guardian. Photograph: AFP via Getty Images, Reuters

The letter Nvidia hosts is not making the distinction that needs to be made. One sentence would have done it. One paragraph could have defined the qualification, published history, disclosed data, reproducible evaluation, and therefore expelled counterfeits like xAI.

The silence is damning. Twenty-five organizations declared openness a security foundation while xAI was loudly counterfeiting it in public, with users’ credentials sitting in a cloud bucket and the repository “open” without any history. Nobody said a word about the breach of “open”, undermining trust in it. Hugging Face, a signatory now embroiled in a huge trust breach of its own, hosts the Grok weights Musk releases on his depreciation schedule, each model opened only as its market value expires. The coalition’s standard is that anything, anything counts toward the “open” cause, including a release engineered to contradict the cause.

Grok 2.5 shipped a xAI license that Tim Kellogg flagged for anti-competitive terms, restrictions that fail the Open Source Definition Wrong on release day. The six-month Grok 3 promise came due in late February 2026. Five months past due, the xai-org account hosts Grok-1 and Grok-2, nothing newer.

The theft

The letter contains one paragraph that performs concrete legal work, and it concerns something other than open weights. On July 21, Treasury Secretary Scott Bessent announced on Fox Business that the government would examine Chinese open models for intellectual property theft and could sanction the companies behind them, citing watermarks from American models found in Chinese systems.

There’s a very technical AI word for it called distillation, but you and I would call it theft

Three days later, twenty-five organizations signed a document declaring distillation “a widely used technique for model improvement, evaluation, and validation” and asking that unlawful extraction be handled through “targeted legal and commercial frameworks rather than sweeping restrictions.

Targeted legal and commercial frameworks means contract disputes and civil damages. The clause converts an announced national security enforcement theory into private litigation between labs. Every open-model developer on the signature list trains on frontier outputs.

The letter therefore has a paragraph deployed as a retroactive legal defense drafted as policy principle. The timing needs to be called out. Axios reported on July 20 that the administration was reviving efforts to restrict Chinese models, that Commerce had previously weighed Entity List designations for Chinese labs, and that closed-lab allies had approached the White House periodically with ban proposals. Then a three-page letter that went through the legal department grinder of twenty-five organizations, with coordinated hosting and a choreographed launch, was in preparation well before the story ran. The leak and the letter reveal a political (profit) battle raging inside the administration, between pro-restriction and pro-access.

The letter’s risk handling then admits that released weights are “beyond the original developer’s control, and modified versions are difficult to trace or reverse.” And it goes on to demand protections “tied to real and demonstrated harms rather than assuming that closed systems are safer by default.” A demonstrated-harm standard applied to a release that can’t be reversed is a lie. It’s like saying don’t let the horses out of the barn after they are gone.

I have no real idea why both of these paragraphs, in full contradiction, survived twenty-five legal department reviews. My guess is because they used AI instead of humans. Put simply, the demonstrated harm is what would kill pre-release vetting, yet the administration is considering pre-release vetting.

The history lacks historians

The letter boils down to a request for the usual stuff. More compute access for startups and researchers. More subsidy, more, moar! Taxpayer money is supposed to go towards shared datasets and evaluation frameworks. That’s another subsidy. And then a request to delay restrictions: basic deregulation. And finally, legal immunity.

Three transfers and an immunity, wrapped in a safety argument. And the elephant in the room is that Musk’s bad-actor behavior refutes all of it.

The letter opens by claiming the lineage of “1980s open-source software pioneers.” The gall. The term open source dates to 1998. The 1980s movement was something different, called free software, launched by Richard Stallman’s GNU announcement of 1983, an ideological project the signatories’ predecessors fought for two decades.

I mean WTAF. IBM? Palantir? Microsoft? You’re telling me these are claiming to hold the open source baton? Microsoft’s own January 2025 manifesto under Brad Smith argued the reverse position, American leadership framed against Chinese competition with export controls attached, and carried the identical asks: public money, public protection, private control.

Their position reversed within eighteen months, while their extraction outcome sounds the same. When the argument flips completely while the bill stays the same, the person billing has a trust problem.

The fix for all this anti-historical mucking about and political buffoonery is definitional and it is short. Openness deserving legal protection has a checklist: published development history, disclosed training data, reproducible evaluation, declared server-side data flows, and attested claims about deletion and retention.

Nvidia ships this when it wants to. It’s not anything unusual. The letter’s signatories can meet it or stop being a wolf in bed putting on grandma’s bonnet. A release with no history, no scope, no server, and no auditor is a failure by design, and Washington is currently being asked to let it continue operating like a Tesla.

The deeper resolution is that irreversibility is the ethics landing.

Publication is a one-way gate, a fact that carries no safety valence on its own. Every party in this fight is working to move scrutiny somewhere else, instead of admitting this tension in the open.

Miessler’s mousetrap article, which I wrote about before here, tried to invent a recall lever that will never work on an open weight model release.

The “harm” of self-hosted models is people make things themselves. All profits from buying this shirt support Techdirt’s ongoing reporting on copyright, technology and innovation. Source: Techdirt Gear

Musk delivered his technology closed first, harvested for months, then burned the evidence at the moment of disclosure, calling the ashes of his “rapid unscheduled disassembly” and exploding Tesla his version of being open.

Now, this NVidia letter’s demonstrated-harm standard needs a remediation phase like a rocket already fired into space needs a launch pad on earth to make repairs. Too late.

All three understand exactly where the demand for proof belongs, which is why they are trying to prevent it from going there. Their arguments for relocation should be called out for what they are, capture and extraction.

The honest position is, as it should always be, the boring one: release can never be undone, therefore release is the last moment evidence can be demanded, so the evidence must be presented on release. It’s the countdown of a rocket fired, “all systems go” meaning systems were actually evaluated. Did the Challenger explosion not teach anyone anything? History, data, recipes, declared data flows, attested deletion.

Lloyd’s Register ran on this logic for two centuries, classification before launch with the records kept in class, and nobody called that survey a restriction on shipbuilding. Hell, the British merchant fleet that fed and funded the war against Napoleon sailed under those survey records, and the insurance industry damn well knew the difference!

Perhaps France’s infamously aggressive “move fast, break things” dictator should be referenced today more often as Mr. Napoleon Blownapart? The gargantuan French warship L’Orient, carrying all the treasure Napoleon looted from Malta, explodes at 10PM and strands the French army in Egypt without a fleet, funds, or a way home. Source: National Maritime Museum, Greenwich, London

Openness that is anchored in transparency, a verification record as the ticket to release, is the actual goal. America needs to stop throwing shallow labels around and get back to empiricism, if it wants to be trusted at all, ever again.