AI Daily Digest — 2026-05-22
Key Highlights GitHub’s internal repos were exfiltrated through a poisoned VS Code extension. Microsoft confirmed a compromised employee device — via the malicious NX Console extension — pulled an estimated 3,800 internal repos. Theo (t3.gg) and security firm Aikido lay out the kill chain: a contributor’s GitHub token stolen in the earlier Shai-Hulud worm wave was used to publish a malicious version that auto-updated to ~2.2M installs in 18 minutes. The marketplace has no staging window, no audit gate, and no takedown push. This is now the second VS Code extension–driven supply chain breach in six months (after Async API in Nov 2025), and credentials harvested by that earlier worm are still being weaponized. The Trump White House paused its AI security executive order over the requirement that frontier labs share models with federal evaluators 14–90 days before launch. The order was triggered by Anthropic’s Mythos and OpenAI’s GPT-5.5 Cyber — both of which can autonomously find and exploit security flaws — but Trump said the pre-release review language “could have been a blocker” and that he doesn’t want anything in the way of “leading China.” Expect a softer redraft and a continued split between national-competitiveness framing and pre-deployment evaluation regimes. Two Day-After-I/O takes converged on the same thesis: Google has the platform but not the execution. The Rundown’s Pichai interview pitches agents as flip-phone-obvious within three years; Theo’s “I’m scared to make this video” walks through Gemini 3.5 Flash’s tripled per-token price, its 2× cost-to-completion vs. 3.1 Pro on real agentic tasks, the closure of the open-source Gemini CLI in favor of a closed Antigravity CLI, and Google Cloud abruptly suspending Railway’s $2M/month account. The pattern shared across both: capability gains are real, but distribution/trust is fraying. OpenAI says a general-purpose reasoning model disproved an 80-year-old Erdős conjecture on unit distances — a novel discrete-geometry result reviewed by Tim Gowers and Noga Alon. Notable because the work came from an upcoming general model, not a math-specialist system like AlphaProof. Sam Altman (with Patrick Collison) and Jensen Huang (with Michael Dell) gave essentially the same diagnosis in different words this week: coding models inflected hard in late 2025, demand has gone “parabolic,” and compute per task is up 100–1000× because agents now plan-act-iterate instead of one-shot replying. Altman thinks OpenAI can stay near-flat on headcount (2× over five years) while scaling output; Huang says Vera CPU + Rubin/Blackwell racks are the substrate for “unmetered intelligence” on-prem. Analysis & Opinion Trump delays AI security executive order, saying language “could have been a blocker” — TechCrunch Trump postponed signing an executive order that would have required AI labs to share advanced models with the Office of the National Cyber Director and partner agencies between 14 and 90 days before public launch. The order was prompted by recent releases from Anthropic (Mythos) and OpenAI (GPT-5.5 Cyber), both capable of rapidly identifying and exploiting security vulnerabilities — exactly the dual-use frontier the EO was meant to address. Trump’s stated reason: he doesn’t want anything “to get in the way” of US leadership over China. CNN reported the unofficial reason was scheduling — too few tech CEOs could fly in for the signing ceremony — but the substantive disagreement over pre-release review remains unresolved. The outcome will likely set the template for how the second Trump administration handles frontier-AI oversight: voluntary commitments and red-team reporting rather than statutory pre-deployment review. Watch for a redraft with the disclosure window stripped or relaxed to post-launch reporting. ...