Today's news lives one floor below the product. A tiny, boring class of model — the "decision model," which answers bounded questions instead of writing prose — went from curiosity to contested category in a week, with Cloudflare shipping an open-weight entry and the most-used minimal agent harness shipping 1.0 with native support for routing to one. Meanwhile arXiv admitted that volunteer moderation cannot survive AI-accelerated submission volume and capped authors at two papers a month, the author of Pro Git argued that Git 3.0's SHA-256 default is about to cost the industry a fortune for a threat nobody has ever suffered, and three separate groups discovered that the five-dollar WiFi chip in your smart plug has been a software-defined radio the whole time. None of these are product launches in the usual sense. All five are the substrate moving while everyone watches the demo.
1. Pi 1.0 ships, and brings a durable sibling
Source: Earendil - https://earendil.com/posts/pi-1-0/
Earendil shipped Pi 1.0, declaring its minimal agent harness stable enough for people and businesses to depend on, and the feature list is a precise map of what the team decided had finally proven itself: Codemode with native MCP support and non-LLM models, extension support for virtual models, deferred tool loading, cache warming for Anthropic models, mid-conversation system messages that let the prompt and toolset change mid-transcript, and full-screen mode by default. Alongside it came Pi Durable, an experimental MIT-licensed package for long-running agentic applications that reach past the terminal. The demo buried at the bottom of the post is the thesis: Pi writes itself an extension defining a virtual model that plans with Claude Opus, implements with GPT 6 Luna, and uses Jev — a decision model, not an LLM — to detect the handoff point and switch. Note what that architecture implies. The expensive frontier model is no longer the whole runtime; it is one stage in a pipeline whose control flow is adjudicated by something small, fast, and cheap. Earendil's stated discipline — wait until a thing proves itself, weigh functionality against added complexity, and let most candidates fall off the wall — is the least fashionable sentence written about agents this year and probably the most load-bearing. Shipping 1.0 three days after publicly reversing a long-held anti-MCP position is not inconsistency; it is what "we wait" actually looks like when the waiting ends.
2. Cloudflare open-sources Clef, and the decision-model category gets real
Source: Cloudflare - https://blog.cloudflare.com/clef-decision-models/
Cloudflare released Clef and Clef-flash, two Apache 2.0 decision models hosted on Workers AI and published on Hugging Face, plus a reinforcement-learning product that lets customers fine-tune them on their own data. A decision model takes inputs and returns typed, bounded answers with probabilities — is this ticket urgent, which team owns it, is this domain phishing — so that code, not a human and not a paragraph of generated text, can route the next action. Clef is API-compatible with Typesafe AI's Jev, carries a 64K context window against Jev's 32K, adds a vision encoder Jev does not have, and currently leads the Jev Decision Index; in Cloudflare's own threat-intelligence pipeline it fetched, rendered, and classified a domain in 2.2 seconds against 4.7 seconds for gpt-oss-120b, which also returned fewer categories. The strategic read is simple and slightly uncomfortable for the labs: a large slice of what we have been paying frontier-token prices for is not reasoning, it is classification wearing reasoning's coat. Cloudflare has correctly identified that the profitable layer is the one invoked ten thousand times per request path, not the one invoked once, and has given it away for free to make sure it runs on their edge. Watch the benchmark table honestly, though — Clef-flash scores 97.73 on home appliances where Jev gets 52.27, and loses When2Call 65.58 to 80.97. "Leader" in a category this young means "winner of the evals someone chose to publish."
3. arXiv caps submissions at two per month as AI papers flood the queue
Source: arXiv blog - https://blog.arxiv.org/2026/10/01/updated-rate-limit-policy/
As of October 1, arXiv limits every submitter to two submissions per calendar month and three active submissions at any time, across all categories — a stopgap, the blog says, while it works out what the new best practice should be. The numbers justify the alarm: 9,869 submissions in September 2016, 20,569 in September 2024, and 40,363 last month, a doubling in two years that generated roughly 9,000 support tickets, with cs.AI alone up more than sixfold. Moderators report exactly the pathologies you would predict — thin papers of narrow scope, "salami" papers slicing one result into many, and dense AI-written submissions — concentrated among a small proportion of authors who consume a disproportionate share of volunteer time, which delays everyone else by days or weeks. This is the first unmistakable case of AI-generated volume forcing a core piece of scientific infrastructure to ration access, and the mechanism deserves attention: arXiv is not filtering for quality, which it cannot do at this volume, it is imposing a quota, which is what institutions do when the evaluation function breaks and the queue does not. A hard cap is crude, it punishes the genuinely prolific alongside the spammers, and it was still the right call. The deeper problem is that the cost of producing a plausible paper fell to near zero while the cost of reading one did not move at all, and the people absorbing that gap are unpaid.
4. Git 3.0's SHA-256 default: a global migration for a theoretical threat
Source: GitButler blog (Scott Chacon) - https://blog.gitbutler.com/git-3-sha-256
Scott Chacon — GitButler founder and author of Pro Git — published a long argument that Git 3.0's plan to default new repositories to SHA-256 will cost the industry enormously for nearly no practical benefit, and the operational detail is the convincing part. New repos initialized with git init get SHA-256; they cannot be mixed with SHA-1 repos; submodules only work across matching formats; forges must label and route both kinds, and today you cannot push a SHA-256 repo to GitHub at all, which Chacon says is probably the main thing delaying 3.0. Converting an existing project rewrites every object, breaks every existing signature, invalidates every SHA-1 hash ever pasted into a link, an email, or a Slack thread, and requires everyone to cut over simultaneously; most of the Git ecosystem's from-scratch library reimplementations have partial or zero support, so any tool that does not shell out to the Git binary will break somewhere. Google, per a recent Emily Shaffer talk, may simply force SHA-1 system-wide internally to hold the line. His alternative is genuinely elegant: stop conflating content addressing with trust, keep SHA-1 as a storage key, and inject an independently computed tree-content hash into the signed headers of commits and tags — an idea Colin Walters' git-evtag has implemented since 2015. His proof of concept checksums Chromium's 35GB, 2.1-million-file tree in five seconds; the Linux tree takes 257ms. I am persuaded by the engineering and only partly by the framing, because "no demonstrated attack" is the argument every ecosystem makes right up until the demonstration, and 2030 NIST deadlines are a real constraint even if the threat model is weak. But the choice between "migrate everything once per broken hash function, forever" and "make signatures carry their own hash, upgradeable in place" is not close.
5. The ESP32 in your smart plug has secretly been a software-defined radio
Source: RTL-SDR Blog - https://www.rtl-sdr.com/various-projects-independently-find-hidden-sdr-capabilities-in-esp32-microcontrollers/
The ESPARGOS team found an undocumented capability in several ESP32 chips that lets firmware bypass the fixed WiFi and Bluetooth radio paths and capture raw IQ baseband samples directly, turning a commodity microcontroller into an internal SDR covering 2.2–2.7 GHz — plus 4.8–6.0 GHz on the ESP32-C5 — at up to 80 MS/s and roughly 13–54 MHz of analog bandwidth depending on the part. The constraint is export bandwidth, not capture: most parts can only ship snapshots to a PC, making them spectrum analyzers rather than general-purpose receivers, though the ESP32-S31 streams continuously at 16 MS/s over Gigabit Ethernet with SoapySDR, GNU Radio, and gqrx support coming. The remarkable part is the convergence: at least two other groups found the same or adjacent capability independently — a Reddit user streaming 80 MS/s off an ESP32-S3 through an FPGA front end, and C5VRX using an ESP32-C5 as a 5.8 GHz FPV video receiver with onboard demodulation into a resistor DAC. ESPARGOS can now do phase-coherent capture, which means direction finding on arbitrary 2.4 GHz signals rather than just WiFi, and the team has deliberately declined to implement phase-coherent transmission because it could be misused — a restraint worth noticing in a field that usually ships first. Billions of these chips are deployed. Three groups stumbling onto the same hidden function in the same quarter suggests the silicon was always more capable than the datasheet, and that the real supply of radio instruments is not what anyone has been counting.
The Professor's Read
The honest summary of today is that the interesting work has moved below the waterline. Nobody launched a frontier model; instead, a commodity decision model got open-sourced, an agent harness shipped the plumbing that lets you route between four models by cost and task, a repository that holds most of physics started rationing submissions, a twenty-year-old hash function got a reprieve on the grounds that it was never a trust mechanism anyway, and a microcontroller turned out to contain an undocumented radio. The connective tissue is that the expensive, visible layer — the frontier LLM, the brand-new algorithm, the purpose-built instrument — keeps getting undercut by something cheap that was already there. I find that genuinely encouraging and slightly ominous in the same breath, because the same dynamic that makes classification cost a tenth of a cent also made publishing a plausible paper cost nothing, and arXiv is the first institution to say out loud that it cannot absorb the difference. It will not be the last. If you want one practical takeaway from a Friday with no keynote: go count how much of your AI spend is answering a question with fewer than ten possible answers, and then go look at what that costs on Workers AI.
References
- Pi 1.0 (Earendil) - https://earendil.com/posts/pi-1-0/
- Pi Durable (Earendil) - https://earendil.com/posts/pi-durable/
- You said no MCP (Earendil) - https://earendil.com/posts/you-said-no-mcp/
- Pi documentation - https://pi.dev/
- Pi source (GitHub) - https://github.com/earendil-works/pi
- Introducing Clef: our open-source decision models, and new RL fine-tuning platform (Cloudflare) - https://blog.cloudflare.com/clef-decision-models/
- Clef on Hugging Face - https://huggingface.co/Cloudflare/clef
- Clef-flash on Hugging Face - https://huggingface.co/Cloudflare/clef-flash
- Clef on Workers AI docs - https://developers.cloudflare.com/workers-ai/models/clef
- Jev Decision Index - https://huggingface.co/spaces/multimodalart/jev-decision-index
- Introducing System One models and Jev (Typesafe AI) - https://typesafe.ai/blog/introducing-system-one-models-and-jev
- Fair Moderation, Equitable Access, and AI: arXiv's Updated Rate Limit Policy - https://blog.arxiv.org/2026/10/01/updated-rate-limit-policy/
- arXiv moderation policy and submission rate limits - https://info.arxiv.org/help/moderation/index.html#submission-rate
- Git 3.0's upcoming SHA-256 default will be a costly mistake (GitButler) - https://blog.gitbutler.com/git-3-sha-256
- Git breaking changes documentation - https://git-scm.com/docs/BreakingChanges
- SHAttered: the first SHA-1 collision - https://eprint.iacr.org/2017/190
- SHA-1 is a Shambles - https://sha-mbles.github.io/
- git-evtag (Colin Walters) - https://github.com/cgwalters/git-evtag
- tree-sha256 proof of concept (Scott Chacon) - https://github.com/schacon/tree-sha256
- Linus Torvalds on hashes and trust (2005) - https://lore.kernel.org/git/Pine.LNX.4.58.0504291221250.18901@ppc970.osdl.org/
- NIST transitioning away from SHA-1 - https://csrc.nist.gov/news/2022/nist-transitioning-away-from-sha-1-for-all-apps
- Various projects independently find hidden SDR capabilities in ESP32 microcontrollers (RTL-SDR Blog) - https://www.rtl-sdr.com/various-projects-independently-find-hidden-sdr-capabilities-in-esp32-microcontrollers/
- ESP-SDR (ESPARGOS) - https://espargos.net/espsdr/
- ESPARGOS: an ESP32 phased array for seeing WiFi - https://www.rtl-sdr.com/espargos-an-esp32-phased-array-for-seeing-wifi/
- C5VRX: ESP32-C5 as a 5.8 GHz FPV receiver - https://github.com/Twotoz/C5VRX
- Hacker News discussion: Pi 1.0 - https://news.ycombinator.com/item?id=49926069
- Hacker News discussion: Pi Durable - https://news.ycombinator.com/item?id=49925969
- Hacker News discussion: Clef - https://news.ycombinator.com/item?id=49923692
- Hacker News discussion: Git 3.0 SHA-256 - https://news.ycombinator.com/item?id=49924179
- Hacker News discussion: arXiv rate limit policy - https://news.ycombinator.com/item?id=49926512
- Hacker News discussion: ESP32 hidden SDR - https://news.ycombinator.com/item?id=49922674
