The Apple Watch Becomes a Watchdog
- • Apple Watch now records everything
- • Anthropic's economic model calculates an extreme scenario by 2030
- • AI researcher Andrew Tulloch unexpectedly leaves Meta after the launch of Muse.
Other People’s Apple Watches Are Now Recording Everything
At its “Surprise and Shine” event on Wednesday, Apple introduced a feature package for the Apple Watch Series 12 and the Watch Ultra 4 called Audio Intelligence, which permanently evaluates the wearer’s acoustic environment via the built-in microphone. It includes four features. Sound Recognition reports sirens, alarms, doorbells, or a crying child and works even when the iPhone is not nearby. Music recognition via Shazam automatically displays the song title and artist in the Smart Stack without needing to tap the widget; this brings Apple on par with Google’s Now Playing.
The two new features are called Live Rewind and Siri Recap. Live Rewind holds spoken language locally in a rolling buffer of about 15 seconds, which is constantly overwritten; a double-press on the Digital Crown transcribes this buffer and shows it as a text snippet on the display. The text can be passed on to Siri or saved in the Siri app; otherwise, it is not stored. Siri Recap does not create transcripts in the background, but rather summaries with a title and key points generated by Apple Intelligence, which can be reviewed later in the Siri app. Unsaved summaries are automatically deleted after seven days.
According to Apple, all four features are opt-in and must be activated individually, with Siri Recap also offering a schedule or location binding (“only at work,” “never at night”) and can be turned off at any time via the Control Center. According to the manufacturer, no audio recordings are created: The S11 chip contains a Secure Exclave, a hardware-isolated chamber that processes the audio separately from the rest of the system and then immediately deletes it, making it inaccessible to watchOS, apps, the user, and Apple itself. Live Rewind transcripts and Siri Recap summaries are, according to the company, end-to-end encrypted, speakers are not identified, and Siri Recap is designed to omit sensitive content like financial data or PINs. When activating Live Rewind, the watch plays a sound, even in silent mode, and a microphone indicator and a full-screen animation appear. For context, Apple has published an eleven-page privacy document on Audio Intelligence.
Live Rewind and Siri Recap will arrive as a beta later this year, starting with English, with more languages to follow; both require the new Siri models and Private Cloud Compute. Functionally, Siri Recap is similar to existing notetakers like Granola or Circleback, which also offer Apple Watch apps. → Apple Support, CNET, TechCrunch, Engadget, Fast Company
Synthszr Take: With the Secure Exclave in the S11, Apple has probably built the most elaborate implementation on the market, yet the watch silently shifts a fundamental assumption: listening used to be an event, but with Siri Recap, it becomes a scheduled state. Calendar data and location labels like “Home” or “Supermarket” then travel to the cloud with the distilled transcript to make the summary look nicer. Only the person wearing the watch gives consent; the colleague in the meeting and the guy at the next table were never asked, and there’s no switch for them either.
Anthropic’s Economic Model Runs Through an Extreme Scenario up to 2030
Anthropic has released an interactive tool called the Econ Scenario Explorer, along with a working paper, that calculates three possible development paths for the U.S. economy through 2030. The underlying model breaks down occupations into individual tasks and estimates which of them will be augmented, automated, or newly created by AI. Cognitive occupations here include management, professional and academic roles, sales, and office work—a very broad segment of knowledge work. The researchers emphasize that these are scenarios and that no probability is assigned to any of them.
In the moderate scenario, AI’s impact is similar to that of the internet: it affects about 4 percent of all tasks in the economy by 2030, the gross domestic product is 1.6 percent higher than without AI, and employment in cognitive occupations decreases by 0.5 percent compared to mid-2026. The unemployment rate reaches 3.9 percent from a baseline of 3.8 percent, and wages rise slightly. In the medium scenario, which the authors call “substantial change,” GDP is 8.3 percent higher, cognitive employment falls by 3.9 percent, and unemployment rises to 4.6 percent. Wages for knowledge workers are 0.3 percent below the path without AI, while other professions earn 5.9 percent more. The transition requires workers like programmers and call center employees to switch to occupations such as electricians or caregivers.
The extreme scenario assumes that AI will affect half of the tasks performed by cognitive workers in 2025, automating 90 percent of them and creating virtually no new cognitive tasks. In this case, GDP would grow by 15.4 percent per year until 2030, economic output would double every 4.5 years, and employment in cognitive occupations would collapse by 21.5 percent. Among those who started in cognitive jobs, unemployment would reach 17.9 percent, their wages would fall by 11.5 percent, and the overall economic unemployment rate would rise to 11.9 percent. The labor share of GDP would drop from 60 to 45 percent. Anthropic cites the Recursive Self-Improvement of AI systems and much faster adoption as drivers.
These figures align with statements from CEO Dario Amodei, who warned in May 2025 that up to half of all entry-level office jobs could disappear by 2030, with unemployment rising to 10 to 20 percent. In the company’s own model, this outcome falls into the most unlikely of the three paths. The model excludes business cycles, financial market disruptions, economic feedback loops, and advances in robotics. Additionally, Anthropic surveyed about 11,000 Americans on expected AI usage, productivity gains, and displacement. The researchers write that it could become clear in one to two years whether this real-world approximation holds, and that economic policy on retraining, income support, or a basic income will determine whether the benefits reach those affected. → Business Today, techstrong, The Decoder, cio
Synthszr Take: Anthropic has built a tool that shrinks its own CEO’s warning down to one of three paths. Amodei’s 10 to 20 percent unemployment figure from May 2025 is now relegated to the extreme case, garnished with 15.4 percent annual growth, which immediately makes the warning sound more palatable. The position behind it is elegant: the company draws the map on which its own forecasts are located and politely passes the distribution question on to policymakers. The 11,000 survey respondents and the openly admitted gaps concerning business cycles, financial markets, and robotics don’t change the fact that a seller is defining the scope of its own product promise here. As a calculating machine, the Explorer is useful, but the calibration of the scenarios should be in the hands of those who don’t stand to gain from their outcome.
Andrew Tulloch Leaves Meta, One Day After Muse Launch
AI researcher Andrew Tulloch has left Meta, about eleven months after joining in October 2025. According to a person familiar with the matter, he delayed his departure until the company had shipped Muse, its new personal AI agent. Neither a reason for his departure nor a new destination is known; Tulloch could not be reached for comment, and Meta has not commented. He worked at TBD Lab, the small frontier research group within the Meta Superintelligence Labs under Alexandr Wang. On his personal website, he described his role at Meta as “working on superintelligence.” This followed one of the industry’s most-discussed recruitment efforts. Tulloch had co-founded Thinking Machines Lab with Mira Murati in February 2025. In August 2025, Mark Zuckerberg reportedly tried to acquire the startup for about one billion dollars; after Murati declined, he approached over a dozen of the approximately 50 employees directly. Tulloch was allegedly offered a package of up to $1.5 billion over at least six years, contingent on bonuses and exceptional stock performance. Meta spokesperson Andy Stone called this account “inaccurate and ridiculous” and also denied the acquisition attempt. Tulloch declined, only to join two months later for what sources described as a significantly smaller package. → implicator, Gizmodo
Synthszr Take: A man turns down $1.5 billion, joins two months later for less money, and leaves after eleven months. Compensation packages buy attendance, and they do so reliably; but there’s no line item for conviction on a paycheck. Meta’s Superintelligence Labs lost at least eight people within two months of its founding, Ethan Knight was gone after just a few weeks, and none of these departures can be explained by a paycheck that was too small. The fact that Tulloch stuck around until the Muse launch speaks to his integrity and at the same time shows how he views the product: as the end of a chapter, not the beginning of one. Zuckerberg has built the most expensive talent market in history, and in doing so, he has overlooked the only currency that truly retains researchers: the belief that they are in the most important place for their work.
Meta’s Agent Muse Demands Access to Users' Inboxes and Credit Cards
Meta has launched Muse, an AI agent for adult US users that requires access to their email inboxes and stored credit cards. According to Linas’s Newsletter, the launch comes 13 days after the company agreed to pay up to $18 billion to settle lawsuits from several US states that alleged Instagram and Facebook were designed to make children addicted to their services. The newsletter argues that this very trust issue forced Meta to create what is, to date, the most complex security design for a consumer agent—an assessment from the author and not an independently verified fact. The analysis names Grok Bot from xAI and Google’s Gemini as direct competitors in the mass market. → Linas from Linas’s Newsletter
Synthszr Take: An $18 billion settlement, and the same people open Instagram again in the evening: Trust as a purchasing criterion is notoriously overestimated in the consumer market. A security design can be replicated in a few months; a lower error rate for bookings, inquiries, and payments cannot. If Muse, Grok Bot, and ChatGPT all pay through the same Stripe Link wallet anyway, the only noticeable difference will be which agent correctly rebooks the flight and which one answers the wrong email.
Meta Offers Up to $300,000 for Security Flaws in Its Agent Muse
Meta has released its personal agent, Muse, and published a blog post detailing the system’s security architecture. According to the company, it has been using Muse internally since early 2026, handing over mailboxes, calendars, and a shell to unsupervised software for the first time, which, according to the text, did not always work as planned. Technically, each user gets their own virtual machine in the cloud where data and credentials are stored; the actual agent environment runs in an isolated runtime cell with filtered system calls and restricted kernel rights. Security-relevant services are deliberately located outside this cell: A service called Sentinel is the sole authorization instance for connector actions and outgoing network traffic and cannot be bypassed by the agent, while a credential service keeps the real OAuth tokens away from the model. → Meta AI Research
Synthszr Take: A manufacturer that writes in its own launch post that handing over mailboxes and shells to unsupervised software 'did not always work as planned' says more about the maturity of personal agents than any demo. The architecture is the consequence of this admission: the agent doesn’t see real credentials, and the instance that decides on actions and outgoing traffic is placed out of its reach because it simply isn’t trusted not to shut it down. The $130,000 for a successful prompt injection on a single user is a price tag on a residual risk that couldn’t be trained away.
Shopify Acquires Tailwind Labs, and With It, the Standard Vocabulary of Web Front-End
Shopify is acquiring Tailwind Labs, the company behind the Tailwind CSS framework. Seeking Alpha reports; the announcement does not specify the purchase price. Tailwind Labs was founded by Adam Wathan and, in addition to the freely available core framework, also develops the commercial component libraries Tailwind Plus and Headless UI, as well as the Heroicons icon set. The framework’s approach, Utility-First-CSS, composes designs using small classes placed directly in the markup, rather than through separate stylesheets. Tailwind is one of the most widely used tools in front-end development and is found in themes, builders, and documentation sites across the industry. → Seeking Alpha
Synthszr Take: Shopify is buying into the layer where web interfaces are first created. Tailwind classes are in millions of templates and in almost every front-end that a language model outputs today, because the training data is full of them. When AI tools generate shops, landing pages, and checkouts, they will be writing in a syntax whose future development will be prioritized in Ottawa.
Thompson vs. Huang’s AGI Declaration: Notes Are No Substitute for Continuous Learning
Ben Thompson, in Stratechery, contradicts the statement by Nvidia CEO Jensen Huang, who had declared on X that AGI has been achieved with the model Astra (according to Thompson, this is already Huang’s second such declaration this year). Thompson counters this and presents his own definition: AGI is an artificial intelligence that learns continuously, meaning it updates its weights during operation. As evidence to the contrary, he describes planning his own home server, where Claude, based on Fable 5 with a knowledge cutoff of January, recommended he wait for falling memory prices, while prices had actually continued to rise through August. As a possible counterargument, he suggests that AGI may have appeared in the form of deterministic software in early 2025 with the launch of Claude Code, i.e., as a Harness that saves notes in Markdown files and loads them back into the context when needed. → Ben Thompson
Synthszr Take: Thompson had a perfectly configured OmniFocus installation that he never actually opened: the tool was there, but the method was missing. Exactly this pattern is now repeating itself in companies that are setting up Markdown storage and memory layers for their agents before anyone can say which decisions even need to be recorded and for what purpose. A log without judgment only produces context garbage faster, which the model then dutifully pulls back into every session.
US Authorities Accuse Six Chinese AI Firms of Industrial-Scale Model Distillation
On September 8, 2026, the NSA, CISA, and FBI published a joint Cybersecurity Advisory with the identifier AA26-251A, in which they accuse six Chinese AI companies of systematically scraping top American models. The companies named are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. According to the authorities, these firms have extracted billions of tokens through millions of requests from variants of Claude, GPT, Gemini, and Grok since at least late 2024, likely with the knowledge of the Chinese government. The process behind this is Knowledge Distillation, where a smaller model is trained on the outputs of a larger one. The agencies describe the technique itself as legitimate but classify the observed campaigns as aggressive, malicious, and targeted, writing that for these companies, distillation is the core of their model development, not a supplement to it.
The advisory lists in detail which model allegedly learned from which. DeepSeek is said to have extracted synthetic training data for R1 and V3 between late 2024 and mid-2025 from Claude 3.7, Sonnet 4, Sonnet 4.5, Opus 4.1, two Gemini 2.5 variants, several GPT versions up to GPT-5, and Grok 4; the publicly stated training costs of $5.6 million are allegedly misleading because they do not include the data obtained this way. Moonshot AI is said to have scraped extensive data since mid-2025 from Claude Fable 5 for Kimi-K3 and from GPT-4o for Kimi-K2, with a focus on agentic reasoning, coding, data analysis, and computer vision. Alibaba is said to have extracted capabilities for its Qwen family from Claude and GPT-5 variants in late 2025, while MiniMax reportedly extracted chain-of-thought reasoning and methods from reinforcement learning and supervised fine-tuning for its M2 model.
The described access routes include native APIs, cloud providers, and third-party aggregators that automatically obfuscate user metadata. There is also a gray market of proxies, called 'transfer stations' in the advisory, used to circumvent geographical blocks and terms of service. Costs are reportedly reduced through bulk purchases of premium subscriptions shared by entire developer teams. The authorities name advanced tactics such as automatically switching to other access routes as soon as one is blocked, as well as rating systems designed to detect whether a response has been intentionally degraded.
The agencies recommend three steps for US providers: detecting suspicious accounts and usage patterns, including comparing subscription and consumption ratios; targeted modification or degradation of responses to presumably malicious queries; and cross-organizational information sharing. Anthropic had previously stated that three Chinese labs had generated more than 16 million exchanges with Claude via around 24,000 fraudulent accounts. Treasury Secretary Scott Bessent announced that sanctions and Entity List entries are an option for covert, industrial-scale distillation, comparing the practice to copying homework. The Chinese embassy in Washington did not initially comment. The advisory comes just over two weeks before the scheduled September 24 meeting between Donald Trump and Xi Jinping in Washington, where AI is expected to be a topic; in parallel, authors, artists, and media companies in the US are suing the same American providers over training data. → CISA, Reuters, CyberScoop, unite, Wall Street Journal, South China Morning Post, KVIA-TV, NBC News, Bloomberg Law, FCW
Synthszr Take: Advisory AA26-251A is freely available on the CISA website, and the most detailed analyses of it from Reuters, WSJ, and Bloomberg Law are behind a paywall. This means the most-read text on this story is the raw text from a government agency, without counterarguments and without examining the question of how technically reliable the attribution of specific training data to specific models can even be. The circulating figures almost all come from biased sources: The 16 million exchanges via 24,000 accounts is Anthropic’s own count, and the reference to the allegedly embellished $5.6 million in training costs for DeepSeek comes from the prosecutors themselves. Free government communication plus paywalled research results in a public that knows the press release better than its verification. Just over two weeks before the Trump and Xi meeting, this is a very comfortable starting position for the side that wrote the original text.

