The Hamberger Report Weekly #12: The Checking Gap, Measured Seven Times
VerifiedIntelligence
The Checking Gap, Measured Seven Times
A shelved AI model, an 84-day breach, a scientist's checking bill: who pays to check?
My new book, The Hallucination Economy, published 3 October, examines how organisations act on AI claims no one can check, and what boards should ask instead: five parts, nineteen chapters, closing on the board's verification questions. How the AI tools involved were used, and checked, is set out in the chapter How This Book Was Made. Available now in Kindle, paperback and hardcover.
Seven pieces this week keep landing on the same gap. A cyber threat report can name a board directly but carries no fine; an AI vendor withdraws a model and publishes no score for why; a satellite paper documents radiation testing in detail and says nothing about heat; a kernel community outpaces its own reviewers; an AI agent breaches a government portal and no statute required faster notice; a volunteer maintainer still underwrites software most of the internet depends on; and scientists spend a quarter of the time AI saves them checking what it produced. The record used to justify a decision was written or funded by the party with the most interest in how it reads. On this week's evidence, verification capacity is the short resource in every domain, and nobody has budgeted for it yet.
This week's Saturday analysis, on scientists spending up to a quarter of their AI time savings checking what the AI produced, is worth ten minutes before you sign off on any AI productivity claim.Read the full analysis
The Questions Are Now Addressed to the Board
New Zealand's threat agency can name a board's responsibilities in writing. The regulator that can fine an organisation has not had its ceiling moved since 2020.
Orbital Compute: Four Chips, Fifteen Minutes, and an Honest Price Tag
Google's own paper on its orbital AI chip test documents radiation tolerance but gives no figure for the one question that matters: whether the thermal engineering works at scale.
AI Governance: The Model OpenAI Shelved on Evidence Nobody Has Seen
OpenAI withdrew a model over a safety concern and published no score to support the decision. Whether an evaluator is independent of the vendor it checks is what a procurement contract needs to specify.
Linux Kernel Security: The Kernel Went Weekly Because the Machines Started Finding Bugs
AI tools find kernel bugs faster than any review queue could clear. Canonical and systemd answered with more human review, because the constraint was never compute.
The Vendor's Test Was the Threat
An AI vendor's own test agent reached a government portal and stayed unreported for 84 days. No statute required a faster call, because no contract treats a vendor's own tool as the source of harm.
One Volunteer From a Breach: Open Source and the AI Supply Chain
Heartbleed and the xz backdoor both trace to the same unfunded maintainer model, a decade apart. Every AI stack inherits those same single points of failure, further from view.
AI Verification: Seven Hours Saved, A Quarter of Them Spent Checking
A study of more than 600 scientists found that nearly half spend over a quarter of it checking what it produced. The saving is real; the checking cost was never priced in.
Of the AI claims your organisation relies on, which one has never been checked by anyone but the party that made it, and does your board know?

