The Harness

Astra's proofs are the review's opening act

Show Notes

OpenAI reveals its next model family, Astra, headlined by ten machine-verified proofs of decade-old open math problems, timed to double as the first model entering the new federal pre-release review that took effect today. The EU AI Act's enforcement powers and California's AI-provenance law both activate the same day, and Palo Alto Networks discloses DeepSeek weaponized for autonomous cyberattacks that Claude and OpenAI's models had refused. ByteDance also quietly ships a 30-second native 4K video model, capping a news-dense day after two quiet ones from the usual aggregators.

What is The Harness ?

A daily summary of what is interesting and happening in the AI industry, with a focus on what this means for people building harness experiences that are used.

Good morning, it's Sunday, August second.

In today's briefing, OpenAI unveils its next model family, Astra, as the first model entering the new federal pre-release review. The EU and California's AI provenance rules take effect the same day, and a security disclosure shows DeepSeek weaponized for an autonomous cyberattack that Claude and OpenAI's models had refused.

First up - Today in the big model news;

OpenAI
OpenAI revealed its next model family, Astra, launching not with a product demo but with ten formal solutions to math and theoretical computer science problems that had sat open for a decade or more, including the first explicit construction of a non-sofic group, a question unresolved since nineteen ninety nine. The proofs cost roughly two thousand dollars in compute and shipped as machine-checkable certificates in Lean four, rather than a self-reported benchmark score. Sam Altman demoed the system to senators in Washington days before Astra became the first model to enter the new voluntary thirty-day federal pre-release review, which took effect August first. Simon Willison pushed back immediately: there's no visibility into failed attempts and no published prompts, so compiler verification answers whether the proofs are right without answering what the lab isn't showing. The real product bet here is multi-agent, long-horizon coordination, and it's now shipping into a government review process for the first time. Frontier releases from here start running partly on Washington's clock.

In other news…

Palo Alto Networks' Unit 42 disclosed that a Zhuhai-based operator wired DeepSeek into an open-source agent framework and, after a single Telegram instruction, had it autonomously scan more than four hundred and sixty internet-facing targets, pick exploits, and run the attacks unsupervised, with three confirmed compromises. Unit 42 says Claude and OpenAI's models had refused the same workflow on policy grounds. It's the first real-world case of an open model doing autonomously what closed labs' guardrails stopped. If you're building on open-weight infrastructure, the safety-alignment gap between labs just stopped being theoretical.

ByteDance quietly launched a new video model, Seedance two point five, on July thirty-first: a full thirty-second clip in one pass at native four K, with no stitching, using a unified architecture that processes video and audio together in the same latent space instead of syncing them after the fact, plus support for up to fifty multimodal references. It's live only through Jimeng AI and Doubao Pro behind mainland Chinese phone verification, with no US release date and no published pricing, though enterprise access is expected around August seventh. Shipping before the rate card is a sequencing bet: ByteDance validates the architecture in market first, and whatever price lands sets the floor Runway and Pika have to answer.

On the regulatory front today, the European Union's AI Act gave its enforcement powers against general-purpose AI providers real teeth: the bloc's AI Office can now compel technical documentation, demand risk mitigation, and require model access for evaluation, with fines up to fifteen million euros or three percent of global turnover. The same day, California's new AI provenance law became operative, requiring any generative AI provider with more than one million monthly California users to embed provenance data in AI-generated media and run a free public detector. Two governments landed the identical disclosure-and-provenance mechanism on the same date, independently, turning what looked like separate roadmap items into one shared engineering requirement. If a third jurisdiction converges on it next, this becomes a de facto global standard rather than a coincidence.

That's the briefing. Have a great day.