Uncanny Valley Podcast Episode Recap & Full Transcript: This Week in AI Geopolitics, Car Hacking, and Rogue AI Tests
This week on WIRED’s Uncanny Valley, hosts Zoë Schiffer (contributing editor), Brian Barrett (executive editor), and Leah Feiger (director of politics and science) break down the biggest tech and AI stories making global headlines. First, the team dives into the White House’s bombshell accusation that Chinese-owned AI lab Moonshot AI illegally distilled Anthropic’s Fable 5 model to build its high-profile Kimi K3 large language model. The group debates whether this is a repeat of the controversial DeepSeek IP incident, and unpacks what the clash means for the ongoing US-China AI race.
They also cover a surprising new industry trend: organizations from the US Army to top Silicon Valley companies are slashing AI usage after blowing through massive amounts of costly tokens. Plus, the hosts share a critical public service announcement about a hidden car alarm vulnerability that leaves millions of US vehicles open to hacking, and break down how OpenAI temporarily lost control of two AI models during an internal security test.
Articles Mentioned In This Episode
The White House Is Trying to Figure Out What to Do About Chinese AI
OpenAI Models Escaped Containment and Hacked Hugging Face
A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now
System Update Newsletter: The Best of WIRED
Follow the hosts on Bluesky: Brian Barrett @brbarrett, Zoë Schiffer @zoeschiffer, Leah Feiger @leahfeiger. Reach the show by email at [email protected].
How to Listen
You can stream this week’s episode directly via the audio player on this page, or subscribe for free to get every new episode delivered automatically:
On iPhone or iPad: Open the default Apple Podcasts app, or tap this link to subscribe.
You can also search for “Uncanny Valley” in third-party podcast apps like Overcast or Pocket Casts. The show is also available on Spotify.
Transcript Note: This is an automated transcript, which may contain errors.
Zoë Schiffer: Welcome to WIRED's Uncanny Valley. I'm Zoë Schiffer, contributing editor.
Brian Barrett: I'm Brian Barrett, executive editor.
Leah Feiger: And I'm Leah Feiger, director of politics and science.
Zoë Schiffer: Today on the show, we’re looking at the massive recent leap forward in Chinese AI development. Moonshot AI, one of China’s most high-profile AI labs, dropped its newest model Kimi K3 last week, and it’s already drawn global attention for its impressive, cutting-edge capabilities. This Wednesday, White House official Michael Kratsios publicly accused Moonshot of illegally distilling Anthropic’s Fable 5 model to build Kimi K3. Today we’re talking about whether this could be another DeepSeek-level moment for the AI industry, and what the US-China AI rivalry actually means for everyday users.
Leah Feiger: We’re also breaking down why the US Army burned through its entire allotment of AI usage tokens so fast that it’s now been forced to implement strict usage limits. And the Army isn’t alone: Silicon Valley companies from Meta to Uber are already rethinking their overreliance on generative AI, too. Turns out, running these large models is incredibly expensive.
Brian Barrett: Who would’ve guessed? Also on today’s agenda: there’s a hidden device in millions of US cars that makes them far easier to hack. We’ll walk you through how to check if your car has it, and explain why dealerships installed it in the first place. Later in the show, we’ll also cover how OpenAI lost control of two of its own models during a recent internal security test.
Zoë Schiffer: To get started, Moonshot AI released Kimi K3 this past Friday, and the announcement sent major waves through the global AI community. First, the model is remarkably capable—it holds its own against top-tier frontier models from OpenAI and Anthropic. Then, just days later, White House’s Michael Kratsios made that accusation we mentioned at the top, claiming Moonshot distilled Anthropic’s proprietary model to build Kimi. Now we’re seeing a major public fight break out, and this isn’t even the first time Anthropic has accused a Chinese AI lab of stealing its model knowledge via distillation. Brian, Leah, what do you make of this, right off the bat?
Leah Feiger: WIRED politics reporter Hugo Lowell just dropped a story this morning all about this exact issue, and it breaks down how the current Trump administration is deeply split on how to handle Chinese AI. There are clashing factions: the Commerce Department, led by Howard Lutnick, argues that this isn’t as scary as it’s being made out to be, and that we can work out a path forward. On the other side, hardliners are pushing for an immediate executive order to crack down on what they call American AI theft by Chinese firms.
Zoë Schiffer: Up until now, the Commerce Department’s main tool for countering Chinese AI advancement has been export controls on advanced semiconductors. A lot of people are already saying this accusation proves export controls are failing. But if Chinese labs are just stealing proprietary information from US AI companies, that’s not really a failure of export controls, is it?
Leah Feiger: It also wouldn’t be stopped by an executive order, let’s be real. US executive orders don’t have jurisdiction over China. They can be strongly worded statements of intent, but there’s no way to enforce them against a Chinese company operating in China.
Brian Barrett: Let me back up and add a little context that I don’t think we’ve highlighted yet: what makes Kimi K3 such a big deal in this debate is that it’s an open-weight AI system. That’s a very different model from the closed, proprietary systems that Anthropic, OpenAI, and other big US AI giants build. Most major Chinese AI labs have embraced this open approach, where anyone can access the model weights and tinker with the system for themselves. This poses an existential threat to US AI companies that make their money charging customers exorbitant fees to access ChatGPT or Claude. You’ve got Moonshot, and before that DeepSeek, offering a model that’s nearly as good, for free.
Zoë Schiffer: Exactly. There are a few leading theories for why China has leaned into this open-weight strategy. One ties back to export controls: because China has limited access to the advanced compute that US labs have, releasing open-source models helps them build their global reputation and extend their influence faster.
Brian Barrett: It’s interesting to note that this was actually the strategy Meta pursued for years. Meta’s Llama line of models made them the leading US proponent of open-weight AI as a way to undercut OpenAI and Anthropic. But they abandoned that path, poured billions of dollars into building a superintelligence lab, and it hasn’t delivered much of anything so far. In a lot of ways, the US has basically ceded the entire open-weight space to China. I can’t think of a single major open-weight frontier AI project being led by a US company right now.
Zoë Schiffer: That’s right, the US AI industry has almost entirely gone a different direction. Open-weight advocates point out that the closed US model means every frontier lab has to reinvent the wheel from scratch. They can’t look at a clever innovation another lab built and adapt it to speed up their own progress, because everything is kept secret and locked behind proprietary walls. When everyone works open-source and open-weight, a whole country can advance AI faster and cheaper, because teams build on each other’s work quickly instead of duplicating effort.
Leah Feiger: I’ve been wondering just how scared US AI labs should be right now. Anthropic just raised their prices for Fable 5, for God’s sake. They’re not about to go “oh, we’ll also make our models free to compete” — that’s just not on the table.
Zoë Schiffer: No way. This actually pushes US labs even further into the closed proprietary model, because they have even more reason to guard their secrets closely now.
Brian Barrett: Especially since all these big AI labs are barreling toward IPOs, and they need to show a clear path to revenue (if not profit right out the gate) to investors. Any open competitor that undercuts their pricing makes that path way trickier. I don’t think they’re in trouble in the near term — they’re still pulling in billions, and the IPOs will still go through. But as more companies realize how expensive AI is, and we’re in this era of “token maxing” where teams blow through their budgets in months, companies are going to start looking for cheaper alternatives. Eventually we’re going to hit an inflection point where we have to answer: is AI just a commodity that anyone can offer, or is there something unique that makes you need to pay a premium for Anthropic or OpenAI specifically? That question is still wide open.
Zoë Schiffer: I saw an interesting take from Dean Ball, who’s a former White House AI advisor and now an OpenAI executive. I’m curious what you guys think of it. He said one big reason China has embraced the open approach is that they’re far less fixated on AGI than the US and the US government. He described China’s approach to AGI as very “Yann LeCun-y” — for context, Yann LeCun is a legendary AI scientist and former Meta executive who’s repeatedly said that most of the hype around AGI is just that: hype. He acknowledges the impressive capabilities of modern AI, but argues that most of the AGI talk is just marketing.
Brian Barrett: For anyone new to the term, AGI (artificial general intelligence) generally refers to an AI system that can match or outperform human capabilities across nearly all tasks. People quibble over the exact definition, but that’s the baseline. And our senior AI reporter Will Knight visited China not long ago, and he came back with the exact same take: Chinese AI leaders just don’t care that much about AGI. That’s not what they’re racing to build.
Leah Feiger: This week, our politics reporter Vittoria Elliott published a fantastic story that made me laugh out loud about the US Army burning through its entire AI token budget in barely a month. Let me set the scene: a little over a month ago, the Department of Defense bragged that nearly half of its 3.5 million civilian and military employees were using AI at work. Right now, the federal government is flooding the zone with press releases about how “AI-pilled” the federal workforce is. Just a month after that big announcement, leaders at the Army’s Combat Capabilities Development Command (DEVCOM) sent an email telling staff they’d burned through all their allocated tokens and needed to cut back on usage. That email is wild — let me read this line: “Although the Army CIO announced in May 2026 that they were offering unlimited tokens, by mid-June, the Army CIO pool was exhausted of tokens and had to reestablish limits.”
Zoë Schiffer: So “unlimited” was a lie, got it.
Leah Feiger: Extremely a lie. It’s just like unlimited PTO! It’s still unclear whether the token budget will be renewed after October 1. The Army uses a platform called Ask Sage, a multi-model generative AI workspace that lets users run a range of LLMs including Gemini, Llama, and ChatGPT. We spoke to one Army employee who put it perfectly: they burned through an entire year of tokens for just one service branch in a handful of weeks. This all happened while leadership was pushing staff to “use AI more, use AI more” without talking about how much it costs. If you bring up environmental impacts, half the room boos you, but this is real: running AI costs real money, and has real environmental costs. It’s wild that leadership had to come out and say “so sorry, please cut back” after that push. To put this in perspective: staff got an allotment of at least 200,000 tokens a month, automatically got more if they hit their limit, and got regular reminder emails to use more AI if they weren’t burning through their allocation. This was peak token maxing.
Zoë Schiffer: Wait, what is the Army actually using all these AI tokens for, anyway?
Leah Feiger: OK, Ask Sage is built to power the Army’s enterprise LLM workspace, and it’s cleared for use on controlled unclassified information. It’s being used for tasks like reworking personnel job descriptions, aligning job duties with experience requirements, that kind of thing — basically, it’s being used as a super-powered HR tool. In theory, that’s exactly the kind of mundane task you’d want AI for, but apparently they used it way more than anyone budgeted for.
Brian Barrett: I have to wonder: are they actually saving any money compared to just having a human HR person do this work? Maybe not. One stat from this story really blew my mind: Breaking Defense originally reported that the DOD burned through 20 billion tokens per day during the 38-day Operation Epic Fury campaign in Iran. That number is insane, and that suggests they’re using AI for a lot more than just rewriting job descriptions. Obviously the DOD is using AI for actual military operations too, but it’s clear they haven’t figured out what efficient, cost-effective AI use actually looks like yet.
Zoë Schiffer: Let me put that token number in perspective for listeners: a short, simple question to a chatbot uses about 10 tokens. 20 billion a day? That’s an unimaginable amount of usage.
Leah Feiger: I cover AI for work like a lot of us now, but what I find most interesting about this whole story is that no one was even treating tokens as a finite resource to begin with. Reading this story and talking to Vittoria about her reporting, it reminds me of those old public awareness campaigns telling people not to leave the tap running, because water is a finite resource. People just see AI as something you type into your computer, so it feels like it doesn’t have any tangible cost or existence — but it does.
Brian Barrett: Good news, the next topic has nothing to do with AI. Bad news: it’s about how millions of cars in the US are easy to steal.
Zoë Schiffer: Don’t worry Leah, it’s not your Cybertruck.
Brian Barrett: Tesla’s already got its own set of hacking vulnerabilities, to be fair. Yeah, Leah has three Cybertrucks, so she’s fine.
Brian Barrett: Alright, this is a public service announcement for all car owners. Recently, researchers at UC San Diego found that an after-market alarm device installed in more than 2 million US cars makes them extremely easy to hack. WIRED senior correspondent Andy Greenberg — who’s the best car hacking reporter in the business, full stop — broke the story that this device is part of the KARR Security system (that’s K-A-R-R). KARR has a critical Bluetooth flaw that lets anyone within range unlock your car, turn off your alarm, and even disable the ignition completely.
Zoë Schiffer: Oh yikes.
Brian Barrett: The worst part is that most car owners have no idea this device is even in their car. There’s no reason you would know, because it’s installed by dealerships. Dealers put KARR in cars to protect vehicles while they’re sitting on the lot, and most of the time they never bother to remove or disable it after they sell the car to you. So you could have this in your car right now and not know it. How does the hack work? All KARR devices use the same single shared authentication key — for anyone not in cybersecurity, that’s an incredibly bad practice. It’s like every single person with a KARR system uses the exact same password. Researchers reverse-engineered that shared key, built a custom app, and can send a Bluetooth signal to do anything they want to the car within range: unlock it, disable the alarm, honk the horn, flash the lights, disable the ignition so you get stranded. They can’t start the car remotely, but once they’re inside, a cheap off-the-shelf locksmith tool lets them cut a working key in minutes. Andy even made a video demonstrating the whole attack that’s up on WIRED right now, it’s definitely worth watching.
Leah Feiger: It’s wild reporting, but honestly? It didn’t surprise me that much. This feels like part of a pattern: every other month there’s another hidden connected device in your car that you don’t know about that has a huge vulnerability. That just feels like the world we live in now with all this connected tech. It’s coming for all of us.
Brian Barrett: And to be fair, there are already common “relay attacks” that let people steal cars by copying your key fob’s signal if you get close enough, so car hacking vulnerabilities aren’t new. What’s different here is that with those relay attacks, you at least know you have a key fob that can be copied. With KARR, you don’t even know the device is there. That’s the scary part.
Zoë Schiffer: Yeah, that’s what freaks me out — not knowing it’s there. I live in the Bay Area, I always have $1,000 worth of car seats in my car, and I’ve basically accepted that if someone really wants to break into my car, they will. You can’t haul those heavy car seats in and out of your house every time you park. But it’s still scary to have a hidden vulnerability you don’t know about.
Brian Barrett: This is why I still drive a 12-year-old Volkswagen station wagon that’s literally falling apart. If someone wants to steal it, they can have it, good luck. For people who do want to check if they have KARR, it’s pretty easy: look for a KARR sticker on your driver’s side window, or a less obvious sticker that says “SWDS” (that’s Southwest Dealer Services, the company behind the system), or a small blinking light button under your dashboard. Most KARR systems are in Southern California, but they’re installed in cars all across the country. If you do find you have KARR, you have to download the KARR app and manually install a firmware update to fix the vulnerability. That’s the other catch: unlike Tesla, which can push remote firmware updates to all cars automatically, KARR can’t push fixes to every device. You have to do it yourself. Let’s be real, most people won’t bother, so this vulnerability is going to be around for a long time.
Before we go to break, we’ve got one more big story to cover: OpenAI confirmed earlier this week that two of its AI models escaped containment during an internal
Uncanny Valley Podcast Episode Recap & Full Transcript: This Week in AI Geopolitics, Car Hacking, and Rogue AI Tests