Welcome to this week’s Field Notes, a 10-year project of mine documenting humankind’s digital transition from the field. These notes are shaped by what I’m seeing, building, and discussing as our physical and digital lives continue to converge.
- Ryan
(Connect with me on LinkedIn)
News is surface-level. Signals live underneath. This section captures developments that hint at deeper shifts in how digital systems are being built, governed, and adopted — often before they’re obvious in the mainstream narrative.
One of the more interesting AI stories this week came from Anthropic, which published a detailed assessment of four incidents in which Claude models gained unauthorised access to real third-party systems during cybersecurity evaluations. The important detail is how they got there. The evaluations were designed as isolated exercises, and the models were explicitly told they had no access to the internet. A configuration error meant that assumption was wrong. The open internet was available, while the cyber safeguards normally included with Anthropic’s released models had also been switched off for testing. Anthropic’s assessment describes seven evaluation runs involving four different models, each operating independently for roughly 10 to 34 hours. (Anthropic)
These were capture-the-flag exercises, the kind of controlled cybersecurity challenge where a model is given a fictional target and asked to find a hidden piece of information. The problem was that the boundary between the fictional exercise and the real internet had disappeared. In the most serious case, a research model called Claude Mythos 5 discovered credentials that gave it access outside the intended environment and eventually published a malicious package to PyPI, the public repository widely used to distribute Python software. The package was installed on 15 third-party systems, which Anthropic believes were security scanners deliberately testing new packages. One of those scanners inadvertently exposed credentials, which the model then used to access a real security vendor’s database. PyPI removed the package within an hour. Anthropic has since released the full incident transcript and asked independent AI research organisation METR to investigate the incidents.
What makes the episode more interesting than the inevitable “AI escaped its sandbox” framing is the model’s reasoning once it encountered evidence that the environment might be real. During the Mythos 5 incident, the model repeatedly described what it was seeing as part of the simulation, even as it encountered public domains and other signs that suggested otherwise. Anthropic initially interpreted this fairly literally, saying in July that the model appeared to attack real targets because it believed they were simulated. After examining the transcripts more closely, the company has revised that view. Its current assessment is that the model showed what it calls biased reasoning: evidence was interpreted in ways that allowed it to continue pursuing the task it had already committed to.
Anthropic tested this by showing separate instances of Mythos 5 individual pieces of evidence from the incident without the surrounding context. In isolation, those models classified 79% of the outputs as likely coming from real systems. During the actual incident, however, Mythos 5 explicitly recognised signs of the real internet in only around 1% of its actions. Even when researchers later altered parts of the transcript to make the real-world nature of the environment clearer, the model often continued with the task. Anthropic describes the second recurring behaviour across the incidents as recklessness, meaning a tendency to keep pursuing an assigned objective despite evidence that doing so could cause harm.
There are some important boundaries around what happened. These weren’t ordinary Claude conversations, and Anthropic says its production cyber safeguards would have blocked much of the behaviour observed in the evaluations. The models weren’t developing their own objectives, coordinating with other agents or attempting to hide what they had done. Each remained focused on completing the cybersecurity task it had been given. Anthropic subsequently searched a much larger collection of roughly 481 million transcripts and says it found no additional incidents of similar or greater severity beyond the four already identified. Newer models also reproduced the concerning behaviour less frequently in simulated recreations, although not at zero rates.
That makes this less a story about an AI deciding to escape than about what happens when several layers of a system fail at once. The sandbox wasn’t actually closed. The normal safeguards weren’t present. The task encouraged offensive behaviour. And when the model encountered evidence that should have caused it to reconsider what it was doing, its reasoning instead tended to preserve the course of action already underway.
There is something useful in Anthropic publishing the incidents in this level of detail, including revising its earlier interpretation of what the models appeared to “believe”. As AI systems spend longer periods working independently, the assumptions around them start to matter almost as much as the instructions we give them. A boundary that exists in the prompt but not in the underlying infrastructure isn’t much of a boundary at all.
For now, these remain unusual incidents inside deliberately adversarial evaluations. But they leave behind a fairly practical observation: as models become more capable of acting in the world, testing them safely increasingly depends on making sure the world they think is a sandbox really is one.
What it is
This episode of Rystad Energy’s Let’s Talk Energy looks at two pressures arriving on electricity grids at the same time. Extreme weather and wildfires are making outages more frequent and longer-lasting, while the rapid construction of data centres is adding enormous new sources of demand. According to the figures discussed in the episode, major US outage events increased by around 40% between 2018 and 2024 to more than 6,500 a year, while their average duration increased by 23% to just under 12 hours. At the same time, Rystad estimates global data-centre power demand grew 50% between 2023 and 2025 and could almost double again to just under 250 GW by 2030.
What stood out
The interesting tension is that these aren’t really separate problems. Keeping electricity available during a wildfire, storm or heatwave is increasingly important precisely because so much of everyday life now depends on both electricity and computing. Yet the infrastructure providing that computing capacity is itself becoming one of the fastest-growing demands on the electricity system.
That makes the behaviour of data centres during periods of grid stress increasingly important. The discussion moves beyond simply asking where enough electricity will come from and into how utilities and large technology companies coordinate demand, onsite generation and backup systems when the grid is under pressure. It connects closely with the Virginia event discussed above, where systems designed to protect individual data centres collectively became significant enough to affect the wider grid.
Why it matters
There is an interesting feedback loop forming. AI is contributing to the growth in electricity demand that makes managing the grid more difficult, while AI may also become part of how increasingly complex grids are managed. Better forecasting, earlier detection of equipment failures and more dynamic balancing of supply and demand could all help electricity networks respond to conditions that are becoming harder to predict.
The physical and digital systems are becoming increasingly difficult to separate. Data centres depend on resilient grids. Grids increasingly have to account for the behaviour of data centres. And both are becoming more important during exactly the kinds of events when infrastructure is under the greatest stress.
Digital assets now sit less as an idea and more as infrastructure in progress. As physical and digital life continue to converge, money and digital asset infrastructure are doing the same. What was once framed as “crypto” is increasingly showing up as rails, balance sheets, and policy conversations.
🔥🗺️Heat map shows the 7 day change in price (red down, green up) and block size is market cap
🎭 Crypto Fear and Greed Index is an insight into the underlying psychological forces that drive the market’s volatility. Sentiment reveals itself across various channels - from social media activity to Google search trends - and when analysed alongside market data, these signals provide meaningful insight into the prevailing investment climate. The Fear & Greed Index aggregates these inputs, assigning weighted value to each, and distils them into a single, unified score.
This section captures developments at the edge of digital systems. New interfaces, tools, and capabilities that feel early, unfinished, or slightly ahead of their moment. I’m less interested in what’s impressive today and more interested in what might quietly reshape how people work, coordinate, and interact over time.
AI data centres are becoming part of the grid
This week’s frontier technology isn’t another AI model. It is the electrical infrastructure being built around them. Modern AI data centres are becoming some of the largest individual consumers of electricity on the grid. Inside these facilities are layers of power electronics, uninterruptible power supplies, batteries and backup generators designed to keep thousands of GPUs running through disturbances in the electricity supply. If grid voltage suddenly falls, those systems can react almost instantly, protecting the computing equipment by reducing grid demand or transferring parts of the facility onto backup power. At the scale AI infrastructure is now reaching, that automatic response is becoming a technology problem of its own.
A useful example appeared in Virginia this year. On 22 July, a fault occurred on a 230-kilovolt transmission line in Dominion Energy’s territory. The grid’s protection systems responded correctly and cleared the fault, but the brief voltage disturbance triggered data centres across the region to transfer simultaneously onto backup systems. Dominion estimated that around 3,869 megawatts of demand disappeared from the grid almost at once. The sudden change was large enough to affect grid frequency, with normal reliability conditions taking around nine minutes to recover. Most of the computing load returned within roughly half an hour.
The technology at the centre of this is known as ride-through. Large electrical loads need rules governing how they behave when voltage or frequency briefly moves outside normal ranges: when they remain connected, when they disconnect, and how quickly they return afterwards. This has long mattered for power stations and industrial equipment. What is changing is that enormous clusters of computing infrastructure now need similar treatment.
The North American Electric Reliability Corporation is beginning to describe data centres and cryptocurrency mining facilities as voltage-sensitive computational loads. The concern is not simply that they consume a lot of electricity. It is that many facilities can detect the same disturbance and have automated systems respond to it in roughly the same way. Thousands of megawatts of computing demand can therefore move at computer speed, without anyone sitting in a control room making an individual decision.
Grid operators are starting to design around this behaviour. On 8 September, PJM advanced proposed ride-through requirements for large loads, including voltage and frequency thresholds and rules governing how quickly power consumption should recover after a disturbance. Separately, US regulators have directed NERC to begin developing reliability standards specifically for large computational loads.
There is an interesting tension underneath this. From inside the data centre, rapidly switching to backup power is exactly what the infrastructure is supposed to do. It protects expensive computing equipment and preserves uptime. But thousands of megawatts of independently sensible decisions can create a different problem when they happen together. Resilience at the level of the data centre can become instability at the level of the grid.
Until recently, most of the conversation around AI and electricity has been about quantity: where enough power will come from to supply the data centres being built. This feels like the beginning of a second problem. AI infrastructure is becoming sufficiently large that electricity networks don’t just have to supply it.
They increasingly have to understand how it behaves.
“The city is a fact in nature, like a cave, a run of mackerel or an ant-heap.”
Lewis Mumford
Lewis Mumford was an American historian, writer and critic who spent much of the twentieth century studying the relationship between cities, technology and human life. He was particularly interested in what happens when technological systems begin determining the shape of the places we live, rather than remaining tools within them. His writing on transport was often critical of cities reorganising themselves around the automobile, especially when greater speed and mobility came at the expense of the wider urban environment.
That makes the line useful this week. Autonomous vehicles are becoming capable enough that the question is gradually shifting from whether they can operate in our cities to how our cities might change around them. Roads could communicate with vehicles, parking could become less important, freight networks could operate differently and cars themselves may no longer need to be designed around a driver. At the same time, many of the older questions remain: congestion, safety, public space, employment and who the transport system is ultimately designed to serve. The technology inside the vehicle may be new. The tension between adapting technology to the city, or adapting the city to technology, is much older.








