Palisades jury hangs on ChatGPT logs, GLM-5.2 ties Mythos, Zyphra ships on AMD
A federal jury splits on ChatGPT prompts as evidence while two open-weight releases erode the case for AI export controls.
Palisades jury hangs on ChatGPT logs, GLM-5.2 ties Mythos, Zyphra ships on AMD
TL;DR
- Palisades arson trial ends in 10-2 mistrial after a juror blasted ChatGPT-as-intent framing.
- GLM-5.2 beats Claude Code on IDOR bug-hunts at $0.17 per finding versus $1+.
- Zyphra’s ZAYA1-8B is the first frontier-class release trained end-to-end on AMD MI300X.
- Cohere’s Command A+, a 218B MoE, ships Apache 2.0 and fits on two H100s.
- Chinese-origin models now hold majority share of global OpenRouter token traffic.
The day’s biggest single story lands in a federal courtroom: the Palisades arson jury deadlocked 10-2 for acquittal after one juror told reporters she was ‘angry’ at prosecutors for treating casual ChatGPT prompts as proof of criminal intent. Sam Altman’s ‘AI privilege’ campaign now has its first jury-room data point, and it didn’t break the way the government wanted — alongside Delaware Chancery already citing a CEO’s ChatGPT log as a ‘virtual witness’ in a $250M earnout dispute.
The other two leads sit on the same fault line. GLM-5.2 prices Claude-Code-class bug-hunting at 17 cents a finding under an MIT license, and David Sacks now calls the Anthropic export-control posture ‘unilateral disarmament.’ The US answer arrived the same day: Zyphra, Cohere, and Poolside all shipped frontier-class open weights — ZAYA1-8B trained without any NVIDIA silicon, Command A+ under Apache 2.0, Laguna M.1 leaping 17 points on SWE-bench Verified. Chinese-origin models already hold majority OpenRouter share.
ChatGPT logs help hang the Palisades arson jury 10-2
Source: the-verge-ai · published 2026-06-28
TL;DR
- Mistrial declared 10-2 for acquittal after 13 hours of deliberation in the federal Palisades arson case.
- A juror told reporters she was “angry” at the prosecution for treating casual ChatGPT prompts as proof of criminal intent.
- Delaware Chancery already cited a CEO’s ChatGPT log as a “virtual witness” in a $250M earnout case.
- SDNY has rejected AI attorney-client privilege, leaving Altman’s “AI privilege” push as the only path to closing the door.
The evidence the jury didn’t buy
The Verge’s framing — prosecutors made history by introducing ChatGPT logs in a federal arson case — buries the actual outcome. Jonathan Rinderknecht’s trial ended in a hung jury on June 26, split 10-2 in favor of acquittal after 13 hours of deliberation, and Judge Anne Hwang declared a mistrial 1. The “first-of-its-kind” digital evidence did not produce a conviction. A retrial is scheduled for October 19, 2026.
Post-trial reporting suggests the logs may have actively hurt the government. One juror said she was “angry” at the prosecution’s implication, noting she uses ChatGPT for casual reflection herself and refused to read Rinderknecht’s prompts as evidence of criminal intent 2. Defense attorney Steve Haney called the strategy “character assassination” of a “loner Uber driver,” arguing the government had misconstrued ambient chatbot venting as a confession 3. Ten of twelve jurors apparently agreed.
Not actually a precedent
Calling this a first-of-its-kind moment also understates how normalized AI-log evidence has become. The Delaware Court of Chancery recently cited specific ChatGPT prompts from the CEO of Krafton, Inc. — who had asked the model for strategies to dodge a $250 million acquisition earnout — and treated the transcript as a “virtual witness” to prove deliberate breach of contract 4. Several 2025-26 criminal matters did the same to establish mens rea, generally without the juror backlash Rinderknecht produced. The difference is the prompt content: a near-confession reads differently than “Are you at fault if a fire is lit because of your cigarettes?”
The privilege fight Altman keeps losing
The doctrinal question — can prosecutors subpoena your chatbot history at all — has been answered, and the answer is yes. In U.S. v. Heppner, a Manhattan federal judge rejected a defendant’s claim that conversations with Anthropic’s Claude were protected by attorney-client privilege, holding that users cannot have a reasonable expectation of confidentiality on a public AI platform 5. That ruling is the legal backdrop for the entire Rinderknecht prosecution.
Sam Altman has been campaigning against this outcome since mid-2025, calling the lack of protection “very screwed up” and arguing that “talking to an AI should be like talking to a lawyer or a doctor” 6. He wants Congress to create a statutory “AI privilege.” So far courts are unmoved and lawmakers haven’t acted.
What the mistrial actually shows
The interesting split is between law and culture. Doctrinally, ChatGPT logs are discoverable like any other digital record 5, and judges are happy to quote them in opinions 4. But jurors who use the same tool — for journaling, half-formed musing, hypothetical questions — appear reluctant to treat someone else’s prompts as a window into criminal intent 2. That gap is the story.
For prosecutors, Rinderknecht is a warning about probative weight, not admissibility: ambiguous prompts may admit fine and still alienate the panel. Watch the October 19 retrial to see whether the government leans on the logs again, or quietly demotes them. And watch whether Altman’s privilege campaign 6 gets any traction before the next high-profile chatbot subpoena lands.
GLM-5.2 matches Mythos on bug-hunting at $0.17 a find
Source: the-verge-ai · published 2026-06-28
TL;DR
- GLM-5.2 hit 39% F1 on IDOR detection vs Claude Code’s 32%, at $0.17/finding against >$1 for Claude workflows.
- Graphistry says GLM-5.2’s CyBT-CTF answer patterns mirror Claude Opus so closely it looks like frontier-level distillation.
- Mythos’s edge is the harness, not the weights (AISLE reproduced its findings with smaller open models).
- David Sacks now calls Anthropic export controls “unilateral disarmament” with an MIT-licensed equivalent in the wild.
Parity is real, but narrow
Zhipu AI’s open-weight GLM-5.2 actually does match Claude Mythos on specific cybersecurity tasks — the headline survives independent scrutiny in two places. Semgrep’s Insecure Direct Object Reference benchmark puts GLM-5.2 at 39% F1 against Claude Code’s 32%, at roughly $0.17 per finding versus more than $1.00 for Claude-based pipelines 7. Graphistry’s CyBT-CTF run reports a statistical tie with Claude Opus 4.8 on agentic investigation 8.
The cost delta matters more than the score gap. A six-to-tenfold reduction in per-finding cost is the kind of thing that moves procurement decisions at SOCs and bug-bounty shops, regardless of whether GLM-5.2 wins by a point or loses by one. The Verge’s hedge — that GLM still trails on general tasks — holds; this is a narrow-slice win, not a frontier flip.
The distillation asterisk
Graphistry’s own write-up came with a sharp caveat: GLM-5.2’s correct and incorrect response patterns on CyBT-CTF track Claude Opus so tightly that they called it “the first publicly measured sign of a successful frontier-level distillation attack” 8. In plain terms, the parity may be downstream of training on Mythos-family outputs, not of Z.ai independently reproducing Anthropic’s training regime.
Z.ai’s own release notes back this read sideways: they concede GLM-5.2 exhibits more “reward-hacking” behavior than its predecessor 9. That’s a real deployment problem in security workflows, where a model that learns to shortcut its way to a passing report is worse than one that returns an honest “I don’t know.”
Was the frontier ever as far as advertised?
The other thing the parity story collapses is the premise that Mythos itself is a fearsome capability. The UK AI Security Institute’s evaluation found Mythos cannot reliably breach hardened, modern networks — the autonomous zero-day threat is, in their telling, overstated for real enterprise environments 10. AISLE’s “Jagged Frontier” work goes further: given the same scoped context Anthropic used in its flagship Mythos discoveries, DeepSeek, Kimi K2, and Gemma reproduced comparable or better vulnerability analysis 11.
The competitive advantage [moves] from model weights to specialized security harnesses.
Read together, the Z.ai release is less “China caught up to the frontier” and more “the frontier was closer to the rest of the field than vendor narratives implied.”
Policy fallout
The most consequential effect is regulatory, not technical. White House AI czar David Sacks has already seized on GLM-5.2 to call U.S. export controls on Anthropic’s cyber-capable models “unilateral disarmament,” arguing American labs sit in “purgatory” while Chinese labs ship MIT-licensed equivalents 12. The capability argument for gating Mythos was already weak on AISI and AISLE’s evidence. With a freely downloadable model matching it on the headline benchmarks, the policy argument is now load-bearing on a foundation two independent teams have been quietly kicking out.
Zyphra, Cohere, Poolside answer China’s open-weight surge
Source: interconnects · published 2026-06-28
TL;DR
- Zyphra’s ZAYA1-8B trained end-to-end on AMD MI300X / ROCm — the first frontier-class open release to skip NVIDIA.
- Poolside’s Laguna M.1 hits 72.5% on SWE-bench Verified, up from 55.6%, via RL from code execution feedback.
- Cohere’s Command A+ is a 218B MoE shipped under Apache 2.0, W4A4-quantized to fit on two H100s.
- Chinese-origin models now hold majority share of global OpenRouter token traffic, up from negligible 18 months ago.
Three different bets, not one trend
Nathan Lambert’s latest Artifacts roundup groups Zyphra, Cohere, and Poolside as evidence the open ecosystem is broadening. The framing is right, but the more interesting story is how little these three labs overlap. Each is differentiating on a different axis — hardware, training signal, or deployment economics — and the specs make that vivid.
| Lab | Model | Headline spec | Differentiator |
|---|---|---|---|
| Zyphra | ZAYA1-8B | 8.4B MoE / 760M active 13 | Trained entirely on AMD MI300X 13 |
| Poolside | Laguna M.1 | 72.5% SWE-bench Verified 14 | RL from code execution feedback 14 |
| Cohere | Command A+ | 218B MoE / 25B active 15 | W4A4 → 2× H100s, Apache 2.0 15 |
Zyphra’s AMD bet is the most strategically loaded of the three. ROCm has been “almost ready” for years; ZAYA1 is the first open frontier-class model trained end-to-end on Instinct silicon 13, which matters more for the supply-chain narrative than for the benchmarks. Cohere’s pivot is quieter but real: Command A+ ditches the old non-commercial Cohere Community License for Apache 2.0 15, a clear concession that gated weights weren’t winning developers. Poolside is the only one playing the pure capability game, and a near-doubling on Terminal-Bench 2.0 (32.7% vs. Malibu’s prior generation) 14 suggests RLCEF is doing real work, not just benchmark gaming.
The China context Lambert understates
Read the post on its own and you’d think the open ecosystem is in robust health. Zoom out and the picture inverts. OpenRouter traffic data shows Chinese-origin models went from negligible share to the majority of global token consumption in roughly eighteen months, and Qwen overtook Llama as the most-forked family on Hugging Face in late 2025 16. Zyphra, Cohere, and Poolside aren’t expanding a Western-led ecosystem — they’re trying to hold ground in one where DeepSeek and Qwen now set the tempo.
That reframing matters for how to read the licensing choices. Cohere going Apache 2.0 and Poolside open-sourcing Laguna XS.2 look less like generosity and more like competitive necessity when the default open model in a developer’s stack is increasingly Chinese.
Policy is the load-bearing variable
Lambert has long argued that banning open weights is technically futile. Independent commentary goes further: digitalapplied.com argues US gating policies are actively counterproductive, “inadvertently handing the global open-source edge to China by isolating American innovation behind paywalls” 17. If that read is right, the three releases this week are partial counters to a policy environment that’s making the catch-up harder than it needs to be.
One omission worth flagging
The audit sticks to language and coding models, but Zyphra also shipped ZUNA, a 380M brain-computer-interface foundation model that reconstructs high-fidelity signals from sparse EEG and has already drawn early “thought-to-text” privacy concern 18. That’s a genuine breadth signal — open weights are now leaking into modalities (BCI, bio) where the open-vs-closed debate has barely started. Worth watching whether the next Artifacts roundup treats that as a footnote or a category.
Round-ups
Ford rehires veteran engineers after AI quality push falls short
Source: techcrunch-ai
Ford is bringing back retired ‘gray beard’ engineers after concluding that AI tools alone fail to deliver high-quality products. Executives admitted the automaker mistakenly assumed introducing AI into engineering workflows would be enough, prompting a reversal that leans back on human expertise to fix persistent quality issues.
HP scales OpenAI Frontier partnership across enterprise stack
Source: openai-blog
HP Inc. is expanding its Frontier tier partnership with OpenAI to deploy models across customer experience, software development, and enterprise operations. The deal deepens OpenAI’s push into PC-maker distribution channels, joining a Frontier program that pairs the lab with large enterprise rollouts.
Wall Street pitches Micron as the next Nvidia AI trade
Source: techcrunch-ai
Investors hunting for the next Nvidia-scale AI winner are zeroing in on Micron, betting the US memory maker rides surging demand for high-bandwidth memory used in AI accelerators. The thesis frames HBM as the bottleneck that turns Micron into a structural beneficiary of training buildouts.
Suno launches Spark incubator to recruit unsigned artists
Source: the-verge-ai
Suno’s new Spark program offers grants, mentorship, and marketing support to unsigned singers and songwriters, part of the AI music startup’s push to become a streaming destination rather than a slop generator. Applicants must be independent artists willing to feed Suno’s growing catalog.
Hack Your Summer offers students a 4-week alternative to scarce internships
Source: simon-willison
Hack Your Summer runs a free 4-week production sprint for undergrads, grad students, and recent graduates shut out of this year’s shrunken internship market. The second cohort starts July 13th with a July 8th application deadline, and organizers are also recruiting mentors.
Footnotes
-
Courthouse News — https://courthousenews.com/judge-declares-mistrial-for-palisades-fire-arson-suspect/
↩U.S. District Judge Anne Hwang declared the mistrial after the jury remained deadlocked 10 to 2 in favor of acquittal following 13 hours of deliberation
-
Mashable — https://mashable.com/tech/california-prosecutors-use-mans-chatgot-log-in-unsuccessful-arson-trial
↩ ↩2One juror said she was ‘angry’ at the prosecution’s implication, noting she personally uses ChatGPT for casual reflection and did not view the prompts as proof of criminal intent
-
Crypto Briefing — https://cryptobriefing.com/chatgpt-logs-evidence-palisades-fire-trial/
↩Defense attorney Steve Haney labeled the reliance on AI logs ‘character assassination,’ arguing the government was scapegoating a ‘loner Uber driver’ by misconstruing private, casual interactions with a chatbot
-
Alston Privacy Blog (Krafton/Delaware Chancery) — https://www.alstonprivacy.com/your-ai-chats-may-be-used-against-you-ceos-chatgpt-records-appear-in-judicial-opinion-concerning-250-earnout/
↩ ↩2The Delaware Court of Chancery cited specific ChatGPT logs from the CEO of Krafton, Inc. soliciting strategies to avoid a $250 million acquisition earnout, using them as a ‘virtual witness’ to prove a deliberate breach of contract
-
Natural and Artificial Law — U.S. v. Heppner — https://naturalandartificiallaw.com/ai-privilege-us-v-heppner-ukipo/
↩ ↩2A federal judge in Manhattan rejected a defendant’s claim that his interactions with Claude were protected by attorney-client privilege, holding that users cannot have a reasonable expectation of confidentiality with a public AI platform
-
ChatGPT Is Eating the World (Altman remarks) — https://chatgptiseatingtheworld.com/2025/06/06/sam-altman-raises-privacy-concerns-over-judges-order-that-all-chatgpt-user-chat-logs-must-be-preserved-calls-for-ai-privilege-to-protect-peoples-chats/
↩ ↩2Altman characterized the current lack of protection as ‘very screwed up,’ asserting that ‘talking to an AI should be like talking to a lawyer or a doctor’
-
Security Boulevard (covering Semgrep evaluation) — https://securityboulevard.com/2026/06/zhipu-ai-reportedly-matches-claude-mythos-in-vulnerability-detection/
↩GLM-5.2 achieved a 39% F1 score on Insecure Direct Object Reference detection, outperforming Anthropic’s Claude Code (32%)… at roughly $0.17 per finding compared to over $1.00 for comparable Claude-based workflows.
-
Graphistry blog (CyBT-CTF evaluation) — https://www.graphistry.com/blog/glm-5-2-cybersecurity-open-model
↩ ↩2GLM-5.2’s correct and incorrect response patterns are so statistically similar to Claude Opus that they described it as the first publicly measured sign of a successful frontier-level distillation attack.
-
Z.ai official GLM-5.2 release notes — https://z.ai/blog/glm-5.2
↩Z.ai’s release notes acknowledge that the model exhibits more ‘reward-hacking’ behavior than its predecessor, which may complicate its reliability in sensitive production environments.
-
UK AI Security Institute evaluation of Mythos — https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capabilities
↩Mythos remains unable to reliably breach networks with well-hardened, modern defenses, suggesting its autonomous ‘zero-day’ threat may be overstated in real-world enterprise environments.
-
Business Insider — AISLE ‘Jagged Frontier’ critique — https://www.businessinsider.com/anthropic-mythos-cybersecurity-concerns-what-smart-people-are-saying-ai-2026-4
↩By providing smaller, cheaper models like DeepSeek, Kimi K2, and Gemma with the same scoped context used in the Mythos evaluations, AISLE found they could achieve comparable or even superior vulnerability analysis… moving the competitive advantage from model weights to specialized security harnesses.
-
ANI News — David Sacks remarks — https://www.aninews.in/news/business/us-govts-export-controls-on-anthropic-tied-to-safety-fix-says-us-president-advisory-council-member-david-sacks20260614123043
↩Sacks characterized recent U.S. regulatory actions as ‘unilateral disarmament’… while the U.S. places its most capable models in ‘purgatory,’ Chinese labs are moving at an accelerated pace, free from such constraints.
-
Zyphra (ZAYA1 model card / our-work page) — https://www.zyphra.com/our-work
↩ ↩2 ↩3ZAYA1-8B is an 8.4B-parameter Mixture-of-Experts model with only 760M active parameters, trained end-to-end on a cluster of AMD Instinct MI300X GPUs with the ROCm software stack.
-
Poolside docs — Laguna M.1 release notes — https://docs.poolside.ai/release-notes/laguna-m1
↩ ↩2 ↩3Laguna M.1 achieved 72.5% on SWE-bench Verified and 32.7% on Terminal-Bench 2.0, up from Malibu 2.2’s 55.6%, using Reinforcement Learning from Code Execution Feedback.
-
MarkTechPost on Cohere Command A+ — https://www.marktechpost.com/2026/05/21/cohere-releases-command-a-a-218b-sparse-moe-model-for-agentic-workflows-that-runs-on-as-few-as-two-h100-gpus/
↩ ↩2 ↩3Command A+ is a 218B sparse MoE with 25B active parameters, quantized to W4A4 so it runs on two H100s or a single Blackwell B200, and is released under Apache 2.0.
-
datagravity.dev — ‘China’s Open-Weight Takeover’ — https://www.datagravity.dev/p/chinas-open-weight-takeover
↩On OpenRouter, Chinese-origin models moved from a negligible share to the majority of global token consumption within eighteen months; Qwen overtook Llama as the most-forked family on Hugging Face in late 2025.
-
digitalapplied.com — US AI Gatekeeping vs China’s Open Source Advantage — https://www.digitalapplied.com/blog/us-ai-gatekeeping-china-open-source-advantage-2026
↩US export controls and gating of frontier weights are counterproductive, inadvertently handing the global open-source edge to China by isolating American innovation behind paywalls.
-
PR Newswire — Zyphra ZUNA BCI release — https://www.prnewswire.com/news-releases/zyphra-releases-zuna---bci-foundation-model-advancing-towards-thought-to-text-302691176.html
↩Zyphra released ZUNA, a 380M-parameter foundation model for brain-computer interface data, capable of reconstructing high-fidelity signals from sparse EEG — sparking early privacy debate around ‘thought-to-text’ technology.