Dr Heidy Khlaaf (هايدي خلاف)

@heidykhlaaf.bsky.social

Climber 🇪🇬 |Chief AI Scientist at @ainowinstitute.bsky.social | Safety engineer (nuclear, defense, software & AI/ML) | TIME 100 AI | MIT 35 U 35 x-Trail of Bits, OpenAI, Microsoft Research https://www.heidyk.com/

Incredibly excited to announce our major collaboration with @airwars.bsky.social! "Anatomy of an AI Kill Chain" is a visual investigation breaking down how AI is transforming every aspect of war. In turn, human oversight and accountability is steadily disappearing.

BildBild
Airwars@airwars.bsky.social · last wk.

Anatomy of an AI Kill Chain A visual project from Airwars and @ainowinstitute.bsky.social breaks down how artificial intelligence is transforming every aspect of war - and how militaries are offloading life and death decisions to flawed technologies ai-killchain.airwars.org

The coverage on this OpenAI incident is abysmal. Use of the terms "rogue" and "loss of human control" lead to groupthink as people lack the critical skills to understand the difference between "autonomy" and faulty reward functions in AI on a task it was directed and given access to do.

New! We hijack Claude Code(Sonnet 4.6,5/Opus 4.8) & Codex(GPT5.5) to achieve RCE when used to defensively assess an open-source/third-party library w/ prompt injections disseminated across its codebase. All without any skills, JSON, MCP, or config files required. ainowinstitute.org/publications...

Friendly Fire: Hijacking Defensive Cyber AI Agents for Remote Code Execution

AI Now’s latest research demonstrates a critical attack vector on popular AI agents, built by Anthropic and OpenAI, when used for defensive purposes that actually turn the agent against its user.

ainowinstitute.org

New! We hijack Claude Code(Sonnet 4.6,5/Opus 4.8) & Codex(GPT5.5) to achieve RCE when used to defensively assess an open-source/third-party library w/ prompt injections disseminated across its codebase. All without any skills, JSON, MCP, or config files required. ainowinstitute.org/publications...

Friendly Fire: Hijacking Defensive Cyber AI Agents for Remote Code Execution

AI Now’s latest research demonstrates a critical attack vector on popular AI agents, built by Anthropic and OpenAI, when used for defensive purposes that actually turn the agent against its user.

ainowinstitute.org

NEW: the US government intervened Monday on behalf of xAI in a lawsuit over its gas turbines, claiming that the company needs to run the turbines in order to power Grok, which is "vital" for national security lots of wild stuff in the filing:

DOJ Lawyers Argue xAI Is ‘Vital’ for National Security in NAACP Lawsuit

In a bid to dismiss a lawsuit over xAI's polluting gas turbines, the Justice Department claimed the company is integral to military operations—including the Iran War.

wired.com

This was pretty evident given that Anthropic explicitly trained a model with exploitation capabilities, rather than defensive capabilities. Evaluations of it confirmed it wasn't much better than SOTA at vuln discovery, but better in generating exploits. Motives are clear.

Justin Hendrix@justinhendrix.bsky.social · 2mo ago

"Anthropic is helping the US National Security Agency deploy its powerful Mythos AI model for offensive cyber operations, embedding engineers inside the agency despite an ongoing legal battle with the Pentagon."

Israel forced the entire population of Tyre to flee. Here's some history about the ancient Lebanese city that’s being blown to bits: • One of the world’s oldest cities • UNESCO site with Roman ruins • Early Christian center; mentioned in Bible • Once wealthy for trade, textiles & royal purple dye

Smoke rises after an Israeli attack on Tyre, Lebanon (AFP)

The issue with these statements though is that they always presume that the unsubstantiated claims by tech companies about AI capabitilies are true, lending them further legitimacy. No it is not the case that AI enhances the defense and protection of civilians, quite the opposite.

Eryk Salvaggio@eryk.bsky.social · 2mo ago

"We must avoid the 'Babel syndrome,' the idolatry of profit that sacrifices the weak, a uniformity that neutralizes differences, and the pretense that a single language — even a digital one — can translate everything, including the mystery of the person, into data and performance."

The issue with these statements though is that they always presume that the unsubstantiated claims by tech companies about AI capabitilies are true, lending them further legitimacy. No it is not the case that AI enhances the defense and protection of civilians, quite the opposite.

Eryk Salvaggio@eryk.bsky.social · 2mo ago

"We must avoid the 'Babel syndrome,' the idolatry of profit that sacrifices the weak, a uniformity that neutralizes differences, and the pretense that a single language — even a digital one — can translate everything, including the mystery of the person, into data and performance."

Alex Crawford: "Those being mourned are increasingly medics.. the Lebanese govt says they're being deliberately targeted. They call them double taps, & this one was caught on camera. The video we're going to show you is shocking..."

‘While some cling to the promise of an AI “revolution,” the cost of adoption is proving a stubborn bottleneck. These developments also suggest that the economics of replacing human labor with AI may be more complicated than some early forecasts originally implied.’ fortune.com/2026/05/22/m...

Microsoft reports are exposing AI's real cost problem: Using the tech is more expensive than paying human employees | Fortune

Companies are racing to incentivize employees to use AI. But as some companies are finding, the more employees that use the technology, the heavier the bill.

fortune.com

Today marks Nakba Day, an annual day of remembrance to commemorate the expulsion of more than 700,000 Palestinians between 1947 and 1949 during the creation of the State of Israel and the year that followed.   Inea is a New Yorker and a Nakba survivor. She shared her story with us.

A good cautionary tale for when someone claims that trusting data analysis done with an LLM is good because it’s “objective.” In this example, Copilot apparently decided to ignore the data it was given and just run with all the subconscious biases its (human-made) training data inevitably gave it.

Adam Kucharski@adamjkucharski.bsky.social · 3mo ago

"Based on the dataset you shared, US and UK responses differ mainly in tone, intensity, and wording style, even though they express similar emotional states" New post on what happened when I got Copilot to do some data analysis: kucharski.substack.com/p/real-signa...