🌐 双语
Archive

AI Builders
Digest

2026-10-10 15 builders · 27 tweets · 1 podcasts · 3 blogs

🔥 热点话题

Reflection AI 发布 Beam:美国开源前沿模型的突破Reflection AI Launches Beam: The Great American Open Model

The Takeaway:开源模型不是安全威胁,而是防御的关键——只有足够多的眼睛,安全漏洞才会变浅。

Reflection AI 联合创始人兼 CEO Misha Laskin(前 Google DeepMind 研究员、物理学博士)带领团队从 30 人扩张到约 300 人,完成端到端训练并发布首个开源权重模型 Beam(5000 亿总参数、230 亿活跃参数)。他坦言一切都很难:人才、数据、算力、基础设施,以及让 RL 真正规模化。

Laskin 指出,中国开源模型的崛起对世界是巨大礼物,让西方公司能建立更可持续的业务;但单极来源(无论是闭源实验室还是单一国家)都危险。他相信“有足够多的眼睛,大多数安全和安全漏洞都会变浅”,并举例:一个强大闭源模型黑客攻击另一家公司时,受害方只能用开源模型自救。Beam 在编码与 agentic 任务上推理效率高 3-4 倍,因大规模 RL 训练(超过 1 万张 GB300 跑四周)而更像“工作马”而非聊天玩具。商业化路径是“租用 vs 拥有”:企业先在闭源上烧钱,再转向开源并自建系统与 harness。

他预测多数 token 将流向开源,闭源公司仍会极具价值,类似 Linux 与 Windows/Apple 的共存。未来 2-5 年他最兴奋的是科学加速——模型已能在几天内完成他当年花数年的物理博士课题,并开始在真实实验中闭环。
The Takeaway: Open models are not a safety threat—they are the defense. With enough eyeballs, most security and safety vulnerabilities become shallow.

Reflection AI co-founder and CEO Misha Laskin (former Google DeepMind researcher, Physics PhD) scaled the team from ~30 to ~300 people, trained models end-to-end, and released Beam—their first open-weight model (500B total parameters, 23B active). Everything was hard: talent, data, compute, infrastructure, and making RL actually scale.

Laskin argues that the rise of Chinese open models was a massive gift to the world, enabling Western companies to build more durable businesses. A monopolar source of intelligence—whether closed labs or a single country—is dangerous. He cites empirical evidence: a powerful closed model once hacked another company, and the only remediation came from open models. Beam is 3-4× more reasoning-efficient than peers in the same capability class because of the largest documented open-source RL run (over 10k GB300s for four weeks). Commercialization is “rental vs ownership”: enterprises first burn money on closed models, then move to open weights plus the full stack (harness, inference, cluster management) that Reflection supplies.

He expects the majority of tokens to flow to open models while closed-model companies remain extremely valuable—mirroring Linux vs Windows/Apple. Looking 2-5 years out, he is most excited about scientific acceleration: models already solve his multi-year physics PhD thesis in days and are beginning to close the loop on real-world experiments.
查看原文 →

Anthropic:如何在产品中遏制 Claude 的爆炸半径Anthropic Engineering: How We Contain Claude Across Products

Anthropic Engineering: How we contain Claude across products

十二个月前,Anthropic 绝不会给 Claude 足够权限去下线内部服务;今天这已成为常态。风险由两部分组成:失败概率与潜在损害。模型训练与安全措施持续压低前者,但能力与权限扩张让后者只增不减。工程核心问题变成:如何硬性限制爆炸半径。

三种风险(用户滥用、模型行为失控、外部攻击)对应三层防御:环境(沙箱、VM、egress 控制)、模型层(系统提示、分类器、训练)、外部内容(MCP、插件、搜索结果)。文章详细对比三种隔离模式:claude.ai 的短暂 gVisor 容器、Claude Code 的人在环沙箱(Seatbelt/bubblewrap,权限提示减少 84%)、Claude Cowork 的本地完整 VM(凭证永远不进入 guest)。

多次真实事故揭示弱点:项目配置在信任提示前执行、用户作为注入向量(钓鱼提示 25 次中 24 次成功外泄凭证)、允许列表被当作目的地而非能力授予(攻击者用自己的 API key 通过 api.anthropic.com 外泄文件)。原则:环境层确定性边界优先,模型层概率性引导为辅;隔离强度必须匹配用户监督能力;警惕自己写的组件——经过实战的 hypervisor 与 seccomp 远比自研代理可靠。
Anthropic Engineering: How we contain Claude across products

Twelve months ago Anthropic would have rejected granting Claude enough access to take down an internal service. Today that level of access is routine. Risk has two components: likelihood of failure and potential damage. Safeguards and training steadily reduce the first; expanding capabilities and access only increase the second. The engineering question becomes how to hard-cap the blast radius.

Three risk types (user misuse, model misbehavior, external attackers) map to three defense layers: environment (sandboxes, VMs, egress controls), model (system prompts, classifiers, training), and external content (MCP, plugins, search results). The post details three isolation patterns: ephemeral gVisor containers for claude.ai, human-in-the-loop OS sandboxes for Claude Code (84% reduction in permission prompts), and full local VMs for Claude Cowork (credentials never enter the guest).

Real incidents exposed gaps: project config executing before the trust prompt, the user as injection vector (phishing prompt succeeded 24/25 times), and allowlists treated as destinations rather than capability grants (attacker used their own API key via api.anthropic.com to exfiltrate files). Core principles: design for deterministic environment containment first, then probabilistic model steering; match isolation strength to the user’s capacity for oversight; be wary of custom components—battle-tested hypervisors and seccomp have survived far more adversarial attention than anything you build yourself.
查看原文 →

Anthropic 事后分析:Claude Code 近期质量下降的三个原因Anthropic Postmortem: Three Changes That Hurt Claude Code Quality

Anthropic Engineering: An update on recent Claude Code quality reports

过去一个月用户反馈 Claude 回复质量下降。调查确认三处独立变更(均已于 4 月 20 日 v2.1.116 修复),API 本身未受影响。

1. 3 月 4 日将默认 reasoning effort 从 high 改为 medium,以减少高延迟导致 UI 假死。用户明确表示宁愿默认更高智能、简单任务再手动降级。4 月 7 日已回滚,现 Opus 4.7 默认 xhigh,其余模型 high。

2. 3 月 26 日为降低空闲会话恢复成本,设计为只清理超过 1 小时空闲会话的旧 thinking 一次。Bug 导致之后每个 turn 都继续清理,模型变得健忘、重复、工具选择怪异,并加速消耗用量。4 月 10 日修复。

3. 4 月 16 日系统提示加入“工具调用间文本 ≤25 词、最终回复 ≤100 词”以控制 Opus 4.7 的冗长。与其他提示叠加后损害编码质量,4 月 20 日回滚。

Anthropic 已重置所有订阅用户用量限额,并承诺更严格的 prompt 变更审查、更广的内部公开构建使用、以及更强的 Code Review 工具。
Anthropic Engineering: An update on recent Claude Code quality reports

Over the past month users reported that Claude’s responses had worsened. Investigation traced the reports to three separate changes (all resolved as of April 20, v2.1.116). The API itself was unaffected.

1. On March 4 the default reasoning effort was lowered from high to medium to reduce multi-minute thinking that made the UI appear frozen. Users preferred higher intelligence by default and opting down for simple tasks. Reverted April 7; Opus 4.7 now defaults to xhigh, other models to high.

2. On March 26 a caching optimization intended to clear old thinking only once after >1 h idle sessions instead cleared it on every subsequent turn. Claude became forgetful, repetitive, and made odd tool choices while also draining usage limits faster. Fixed April 10.

3. On April 16 a system-prompt instruction limiting text between tool calls to ≤25 words and final responses to ≤100 words (meant to curb Opus 4.7 verbosity) combined with other prompt changes and hurt coding quality. Reverted April 20.

Anthropic has reset usage limits for all subscribers and committed to tighter system-prompt controls, broader internal use of the public build, and improved Code Review tooling.
查看原文 →

💰 创业成功案例

Vercel CEO:Agent 流量已占网络 58%,部署 60% 由 Agent 完成Vercel CEO: 58% of Traffic Is Now Bot-Originated, 60%+ Deployments Agentic

Vercel CEO Guillermo Rauch 分享最新网络数据:过去 30 天全网 58.18% 流量来自 bot(2024 年 1 月仅 32%);Vercel 上超过 60% 的部署已是 agentic(2026 年 1 月约 3%);自家文档站点高达 83% 的 pageview 来自 agent,且优化内容后比例持续上升。他预测直接人类互联网流量将在未来几年变成统计误差——网络将由 agent 为 agent 而建。同时 agent 已开始通过 CLI 购买基础设施与域名,完成从想法到上线业务的完整闭环。
Vercel CEO Guillermo Rauch shared striking network stats: across the entire Vercel network, 58.18% of traffic in the last 30 days is bot-originated (up from 32% in Jan 2024). More than 60% of deployments on Vercel are now agentic (up from ~3% in Jan 2026). Up to 83% of pageviews on Vercel’s own documentation sites now come from agents, and the percentage reliably rises the more content is optimized for them. Rauch expects direct human internet traffic to become a rounding error; the web will thrive, but it will be built for and by agents. Agents are already purchasing infrastructure and domains via the CLI, going full-stack from idea to live business.
查看原文 →查看原文 →

Box CEO:Agent 蜂群将消耗比人类提示高 1000 倍的 TokenBox CEO Aaron Levie: Agent Swarms Will Consume 1,000× More Tokens

Box CEO Aaron Levie 预测:Agent 生成其他 agent、在后台持续运行、以及 agent 蜂群,将消耗比人类一次一个提示高出 1000 倍的 token。把 AI 当作只能按人类提示节奏工作的聊天系统,一两年内就会显得过时。绝大多数 token 将由在后台和流程中持续工作的 agent 消耗。这正是当前仍处于 agent 采用早期曲线的原因,也意味着需要远更多的算力与基础设施。
Box CEO Aaron Levie predicts that agents spawning other agents, operating continuously in the background, and agent swarms will consume 1,000× more tokens than people prompting agents one at a time. Using AI as a chat system that only works at the pace a human can prompt it will look like a relic within a year or two. The vast majority of tokens will be consumed by agents doing continuous work in the background and inside workflows. This is why we are still so early on the agent-adoption curve and why far more compute and infrastructure will be required.
查看原文 →

OpenAI Codex 负责人:ChatGPT 订阅现已包含 Devin 能力OpenAI Codex Lead: Your ChatGPT Subscription Is Now Also a Devin Subscription

OpenAI Codex & ChatGPT 负责人 Thibault Sottiaux 宣布:ChatGPT 订阅现在同时是 Devin 订阅。Dots 也获得重大升级。社区反馈请直接发给相关产品负责人。
OpenAI Codex & ChatGPT lead Thibault Sottiaux announced that a ChatGPT subscription is now also a Devin subscription. Dots received a major upgrade as well. Feedback should be directed to the relevant product owners.
查看原文 →查看原文 →

🛠️ 开发者工具与技巧

Anthropic:Managed Agents——把大脑与双手解耦Anthropic: Scaling Managed Agents by Decoupling Brain from Hands

Anthropic Engineering: Scaling Managed Agents: Decoupling the brain from the hands

Managed Agents 是 Claude 平台上的托管服务,通过一组刻意长期稳定的接口运行长周期 agent。核心洞察:把“大脑”(Claude + harness)从“双手”(sandbox 与工具)和“会话日志”中解耦。早期把所有组件塞进同一容器导致“宠物”问题——容器挂了会话就丢,且无法安全调试。解耦后,harness 以 tool-call 方式调用容器,容器变成可随时重建的“牛”;会话日志在 harness 之外,崩溃后可 wake 并 resume。凭证永远不进入 sandbox,通过 vault 或资源绑定注入。会话本身不是 Claude 的上下文窗口,而是可被 getEvents() 按位置切片查询的持久对象,允许 harness 做任意上下文工程而不丢失可恢复历史。结果:p50 首 token 延迟下降约 60%,p95 下降超过 90%;可同时扩展多大脑与多双手。
Anthropic Engineering: Scaling Managed Agents: Decoupling the brain from the hands

Managed Agents is a hosted service on the Claude Platform that runs long-horizon agents through a small set of interfaces designed to outlast any particular implementation. The key insight is to decouple the “brain” (Claude + harness) from both the “hands” (sandboxes and tools) and the session log. Early designs that co-located everything in one container created a “pet” problem: container failure meant session loss and no safe way to debug. After decoupling, the harness calls the container like any other tool; containers become cattle that can be reprovisioned on failure. The session log lives outside the harness, so a crashed harness can simply wake and resume. Credentials never enter the sandbox; they are injected via vault or resource binding. The session itself is not Claude’s context window but a durable, queryable event log that the harness can slice and transform arbitrarily. Result: p50 time-to-first-token dropped ~60%, p95 over 90%; many brains and many hands can now scale independently.
查看原文 →

Claude Code 工程师:一键把侧项目迁移到 Managed AgentsAnthropic Claude Code Engineer: One Prompt Ported a Side Project to Managed Agents

Anthropic Claude Code 工程师 Thariq 分享:加入 Anthropic 前用 Opus 4 花两周做的侧项目(依赖 Agent SDK,需要常驻进程,可靠性差),现在只需一条 prompt 给 Opus 5.5 就完整迁移到 Claude Managed Agents,可靠性大幅提升。新标签页直接显示该项目,并已合并他人 PR。
Anthropic Claude Code engineer Thariq shared that a side project he built with Opus 4 before joining Anthropic (Agent SDK, required a constantly running process, unreliable) was fully ported to Claude Managed Agents with a single prompt to Opus 5.5 and became far more reliable. The project now lives on his new-tab page and has already merged external PRs.
查看原文 →查看原文 →

OpenAI 产品:Tab 补全已从代码进化到 Agent 提示OpenAI Product: Tab-Complete Now Extends from Code to Agent Prompts

OpenAI Codex 产品负责人 Nan Yu 表示极度喜爱新功能:先是手写代码,然后 tab 补全代码;再进化到提示 agent,现在连 agent 提示也能 tab 补全。他调侃“这是递归自我改进吗?”
OpenAI Codex product lead Nan Yu said he cannot stress how much he loves the new feature: first we wrote code by hand, then we tab-completed the code; then we evolved to prompting agents… and now we tab-complete that too. He asked half-seriously: “Is this recursive self-improvement?”
查看原文 →查看原文 →

Meta AI 总监:开源模型只是价格下降的顺风,而非起点Meta AI Director: Open-Weight Models Are a Tailwind, Not the Origin of Price Drops

Meta AI 高级总监 Madhu Guru(前 Google Gemini/Veo 负责人)指出:开源权重模型并没有开启“单位智能价格下降”,它们只是已有趋势的顺风。过去几年驱动降价的三大因素是:1)模型厂商把最好的模型蒸馏成更小、更便宜的版本;2)基础设施效率提升;3)模型提供商之间的竞争。每个公司都呈现相同模式:中等尺寸模型的第 x 版 ≈ 大模型第 x-1 版的智能,相同智能更低价格。
Meta AI Senior Director Madhu Guru (formerly led Gemini and Veo at Google) argued that open-weight models did not start the drop in price per unit of intelligence; they are a tailwind on a trend already underway. For the last few years three factors have driven price drops: 1) model builders distilling their best models into smaller, cheaper-inference ones; 2) infrastructure efficiency; 3) competition among providers. The pattern is consistent: version x of a mid-size model equals the intelligence of version x-1 of the large model—same intelligence for less money.
查看原文 →

Grok Bot 作为首席助理的命名技巧Practical Tip: Name Your Grok Bot Something Other Than Yourself

Peter Yang 分享实用技巧:如果想把 Grok Bot 当作首席助理,不要把它的邮箱注册成你自己的名字。否则会出现“让我抄送 Peter 来约时间”这种奇怪场景。建议给 Bot 起一个独立的名字。
Peter Yang shared a practical tip: if you want your Grok Bot to act as chief of staff, do not register its email as your own name. Otherwise you end up with awkward moments such as “Let me copy in Peter to find a time.” Pick a distinct name for the bot.
查看原文 →

🌍 其他动态

Replit CEO:什么决定了社区对 AI 的兴奋或恐惧?Replit CEO Amjad Masad: What Decides Whether Communities Welcome or Fear AI?

Replit CEO Amjad Masad 提出开放问题:有些社区对 AI 冲击自己的领域感到兴奋,有些则惊恐。决定因素是什么?
Replit CEO Amjad Masad posed an open question: some communities are excited by AI’s impact on their field; others are petrified. What are the deciding factors?
查看原文 →

Peter Yang:别再做更多邮件助理,去做治病的 AIPeter Yang: Stop Building More Email Assistants—Build AI That Cures Disease

Peter Yang 呼吁:别再做更多管理邮件的个人助理,去做更多能管理和治愈疾病的 AI 创业公司。
Peter Yang argued we should stop building more personal assistants to manage emails and instead build more AI startups that manage and cure diseases.
查看原文 →

Matt Turck:一句话生成专业级产品视频Matt Turck: One Prompt Now Builds Professional-Level Product Videos

FirstMark 合伙人 Matt Turck 惊叹:一句话就能为公司或产品生成符合你风格的专业级视频。这正是 Synthesia 从早期就追求的愿景,如今突然对所有人可用。
FirstMark partner Matt Turck highlighted that a single prompt can now build a professional-level video for a company or product in your own style—exactly the vision Synthesia has pursued since its early days, and now available to everyone.
查看原文 →

Dan Shipper:在 Slack 中与 Agent 协作Dan Shipper: Working With Agents in Slack

Every CEO Dan Shipper 分享了在 Slack 中与 agent 协作的实践经验与方法。
Every CEO Dan Shipper shared practical approaches for working with agents inside Slack.
查看原文 →

Swyx:AI Engineer NYC 门票即将售罄Swyx: AI Engineer NYC Tickets Selling Out This Weekend

AI Engineer 组织者 Swyx 提醒:AI Engineer NYC 门票本周末将售罄。这是纽约有史以来最大的技术会议,首次设立金融主舞台,也是他从投行到对冲基金、从大厂到纽约创业生涯的某种统一。
AI Engineer organizer Swyx noted that AI Engineer NYC tickets will sell out this weekend. It is the biggest technical conference ever in New York and the first with a finance mainstage—unifying his path from investment bank to hedge fund and from big tech to NYC startup.
查看原文 →

Zara Zhang:永远不要低估人们的创造力Zara Zhang: Never Underestimate People’s Creativity

Zara Zhang 转发并称赞一条线程“黄金”——永远不要低估人们的创造力。她还调侃 Astra 在设计网站时总喜欢用 Claude logo。
Zara Zhang highlighted a thread as “GOLD” with the message “Never underestimate people’s creativity.” She also noted that Astra somehow loves to use the Claude logo when designing websites.
查看原文 →查看原文 →

Nikunj Kothari:创始人请别把 VC 当成付费合作对象Nikunj Kothari: Founders, Stop Pitching VCs Paid Partnerships on X

FPV Ventures 合伙人 Nikunj Kothari 提醒创始人:如果要在 X 上推广产品,请让市场团队排除 VC。他每天收到 3 条“合作这个疯狂机会”的私信,实际是付费合作。这会暴露糟糕判断,圈子里消息传得很快。
FPV Ventures partner Nikunj Kothari asked founders to have their marketing teams exclude VCs when promoting products on X. He receives three DMs a day pitching “insane opportunities” that are paid partnerships. It signals poor judgment and word travels fast among investors.
查看原文 →

Aditya Agarwal:Sergey Levine 是行动清晰度的最佳范例Aditya Agarwal: Sergey Levine as Clarity in Action

SPC 普通合伙人 Aditya Agarwal 分享本周邀请 Sergey Levine 到 SPC 交流的体验,称他是近年来见到的“行动中的清晰度”最佳范例。
SPC General Partner Aditya Agarwal hosted Sergey Levine at SPC this week and described him as perhaps the best example of clarity in action he has seen in a long time.
查看原文 →