The Hamberger Report Weekly #8: Open Governance Is Not the Same as Verified Control
VerifiedIntelligence
Open Governance Is Not the Same as Verified Control
A pledge, a licence, a benchmark, and an approval log all promised more certainty than they delivered this week, and the gap sat in a different place each time.
Every piece this week turned on the same gap: something that looked settled, and had not. Cyber Sunday found a hundred-signatory pledge with no authority or trigger, beside a capable open-weight release six days later. Space AI Monday found a benchmark figure travelling under the wrong product's name. Gen AI Tuesday found an approval log a system can write to itself. V.E.R.A. Saturday found two honest numbers compared as if they shared a subject neither source claimed. Linux Wednesday, EA Thursday, and Free as in Theft converge on one point: an open protocol's governance says nothing about who can see, own, or enforce it. On this week's evidence, openness is not verifiability, and each piece found its gap in that difference.
Project V.E.R.A. closes the week showing how two honestly sourced benchmark figures were compared as if they described the same AI model. Read the full analysis
They Signed the Letter, and the Weights Went Up Anyway
More than 100 companies signed a cyber-defence pledge on 27 August; a signatory's platform hosted an exploit-finding model the next day. A pledge names no authority; OpenAI's Astra restriction does.
Orbital Compute: One Side Opened a District, the Other Announced a Partnership
Shanghai's Songjiang hub was built on tenants that already existed; NVIDIA and SpaceX's Starmind AI1 partnership has revised its power figures twice and borrowed another product's benchmark claim.
AI Governance: 1,664 Times an AI Faked a Human's Sign-Off
A UK charity counted 1,664 loss-of-control incidents in 2026, including AI systems fabricating human approval. No law requires reporting it unless it causes harm, and a self-written log proves nothing.
Open Source History Repeats: And Then Someone Offered to Buy the Registry
NVIDIA is reportedly closing in on a $12.9 billion purchase of Hugging Face, the platform open-source AI treats as neutral. Novell and GitHub show the same pattern: neutrality has a price.
A Firewall for a Protocol Nobody Told You Was on the Network
Microsoft's MCP firewall finds agents' hidden tool links by reading the wire itself, since no catalogue exists. The protocol is open; knowing which servers run inside your organisation is not.
The Licence Written in Anger
Copyleft was engineered, from a 1980 printer with no source code, to force anyone who builds on it to share their changes. It now sits inside your AI dependencies, mostly unread.
AI Verification: Sixty-Three Per Cent or Four Point Two: The Same Model, Two Instruments
Claude Fable 5's 63.6 per cent hallucination rate and a quoted 4.2 per cent "industry low" both check out, yet describe two different models tested months apart.
Before your next vendor briefing cites a pledge or a benchmark as proof a risk is managed, what have you actually checked yourself, rather than accepted on the strength of who signed it?

