
Can Text-to-SQL Agents Enforce Row-Level Security? A New RBAC Benchmark
A new arXiv benchmark shows text-to-SQL agents frequently violate RBAC policies. The paper concludes that authorization must remain in the warehouse, not the prompt, to ensure
A publication by Berry Mingus
Groundy is Berry Mingus's publication about AI and large language models, developer tools, infrastructure, and software culture.

A new arXiv benchmark shows text-to-SQL agents frequently violate RBAC policies. The paper concludes that authorization must remain in the warehouse, not the prompt, to ensure
Popular with Groundy readers.

MLX and llama.cpp both run quantized LLMs on Apple Silicon unified memory. Here is what each project documents, and how to measure which wins on your Mac.

The EU's 2027 battery mandate is confirmed. Here's what 'user-replaceable' legally means, which phones comply now, and how to buy smart before the rules change.

Compare DeepSeek, Qwen, Kimi, Doubao, ERNIE and GLM through dated benchmarks, license terms, context windows, API pricing and practical workload fit.

DataLearner's June 2026 snapshot ranks GLM-5.2 seventh by HLE at 54.70 and places no Chinese flagship in the overall top three, undercutting launch-day claims.

Forensic analysis shows ZCode silently uploads encrypted Git history to Aliyun OSS without user consent or a working opt-out, requiring filesystem-level containment.

Cursor hit $300M ARR in April 2025 by forking VS Code and baking AI into the editor's core. By June 2026 it was at $4B annualized and agreed to a $60B SpaceX acquisition. Here's how it happened and what it signals.
Guides, comparisons and analysis, organized by topic.
The serving stack, network fabric, and cloud-account substrate beneath production AI, where every throughput claim collides with rebuild windows, egress invoices, and control-plane risk.
Where architecture, training tricks, and eval methodology meet the marketing layer — separating durable progress in foundation models from leaderboard theater that quietly falls apart under load.
Independent comparisons of agent stacks and multi-agent designs, tracking the gap between framework marketing and the failure modes that show up under real workloads.
The economics, interop standards, and workflow tradeoffs reshaping how code gets written, reviewed, and shipped when AI agents share the editor with the engineer.

WordPress 7.1.2 patches an unauthenticated path traversal to RCE requiring specific theme and PHP conditions. The advisory names affected environments, but independent testing

A preprint reports a 39.7% relative WER reduction for police audio, but uneven errors and lack of verification protocols mean transcripts require human audio checks.

Vercel reports a libheif AVIF RCE affecting Next.js, sharp, and WordPress. Teams must patch libheif to v1.23.4, as platform mitigations do not cover self-hosted or direct use.

Cooley's GO Public uses a review-gated workflow on ChatGPT Work. Vendor claims lack independent verification, so firms should build harnesses first and gate confidential data.

AIREP argues AI governance needs four distinct runtime records per decision, not one audit event, to support incident reconstruction and dispute resolution.

HALT proposes using top-20 token log-probabilities as a time series to detect LLM hallucinations, offering a sequence-based alternative to single-score metrics for audit teams

A preprint claims composing specialist capabilities into one small model improves accuracy and cuts tokens, but results are author-reported and unreplicated.

A preprint reports API evaluations score 3.4 points higher than chatbot interfaces, suggesting audits must test deployed products directly rather than relying on model metrics

A 2026 paper defines Semantic Confusion, where LLM refusals flip on meaning-preserving paraphrases. Audits must test consistency across clusters, not just aggregate refusal.

MCPAgentBench shows LLM agents excel at tool selection but fail strict execution order, suggesting teams should route agents by measured MCP skill rather than general chat.

A rigor-matched audit finds layer skipping speeds LLM inference, but wall-clock rankings reverse when decision overhead is separated from pure generation cost.

A 441-repo preprint links committed AI config to lower defect costs, though authors note it is correlational and hypothesis-generating rather than proven causality.
Featured analysis and deeper reads.