After the chatbot: judgment, control, and two clocks that are not the same.聊天機器人之後:判斷、控制,以及兩個並不相同的時鐘。
This page is about where the field can go, what to secure this month, and why "quantum plus AGI" is usually two topics forced into one sentence. It does not tell you how to attack a model, a lab, or a person.這一頁談這個領域可以往哪走、這個月該守住什麼,以及為什麼「量子加上 AGI」通常是硬塞進同一句的兩個題目。它不告訴你怎麼攻擊模型、實驗室或人。
Three words, used carefully三個詞,小心使用
01
AI
The field, and the products on this site: models that predict, generate, and call tools. Everything you can buy in October 2026 is AI. Most of it is also narrow, even when the window is wide.這個領域,以及本站的產品:會預測、生成、呼叫工具的模型。2026 年 10 月你買得到的都是 AI。其中多數仍然很窄,就算視窗很寬。
AGI
A system that can learn and carry out most of the cognitive work a skilled person can, including work it was not built for that week. Labs do not share one test. A high score on a benchmark is not this.一個能學習並完成熟練者多數認知工作的系統,包括那一週並不是為它而建的工作。實驗室沒有共用同一個測驗。基準上的高分不是這個。
SI, superintelligenceSI,超智慧
A further claim: a system past the best humans across most cognitive work, including the work of improving AI. People also expand "SI" as "synthetic intelligence." On this desk it means superintelligence. Treat dates attached to it as opinions.更進一步的主張:一個在多數認知工作上超過最強人類的系統,包括改進 AI 的工作。也有人把 SI 展開成 synthetic intelligence。在這張參考台上,它指超智慧。附在上面的日期,當成意見。
AGI, without the poster拿掉海報的 AGI
02
A useful personal test: can you hand the system a messy multi-day job, leave, and trust the result without being a specialist in that job? The agents on this site — Dots, Claude Code, Hermes, OpenClaw — are the first products that make the question feel close. They still need a person who can check. They fail in ways a junior employee fails, plus ways an employee cannot: inventing a citation, spending a token budget, or taking a tool action you did not picture.一個有用的個人測驗:你能不能把一份混亂的多日工作交給系統、離開,並且在你不是該工作的專家時仍信任結果?本站的智能體——Dots、Claude Code、Hermes、OpenClaw——是第一批讓這個問題感覺接近的產品。它們仍需要一個能檢查的人。它們會以初級員工的方式失敗,再加上員工做不到的方式:發明一則引用、花掉 token 預算,或做出你沒想像到的工具動作。
When GPT-6 Astra launched in early September 2026, OpenAI's public framing was an "AGI era." That is a company's sentence about its own release. The same month, independent measurement still showed a spread: Opus 5.5 at 58, Sonnet 5.5 at 56, Astra and Gemini 4 Argon at 53, Sol at 52, on one index, at stated effort levels. A field with that spread, and with effort settings that change the score, has not collapsed into a single finished intelligence.GPT-6 Astra 在 2026 年 9 月初發表時,OpenAI 的公開框架是「AGI 時代」。那是一家公司對自己發布的一句話。同一個月,獨立測量仍顯示一組差距:Opus 5.5 是 58,Sonnet 5.5 是 56,Astra 與 Gemini 4 Argon 是 53,Sol 是 52,在同一個指數、在寫明的努力等級上。一個有這種差距、而且努力設定會改分數的領域,還沒有收成單一完成的智慧。
What is real, and enough to plan around:真實、而且足以拿來規劃的是:
Professional tasks with tools — code, documents, a browser — are now a product category, not a demo.帶工具的專業任務——程式、文件、瀏覽器——現在是一個產品類別,不是展示。
Open weights are close enough that a workstation does private office and coding work. See the advisor.開放權重已經接近到工作站可以做私人辦公室與程式工作。見顧問。
The scarce inputs are evaluation, permission, electricity, and the price of a finished task.稀缺的投入是評估、權限、電,以及完成一件任務的價格。
Labor effects are uneven and already visible. California's late-September worker statutes treat AI in hiring and monitoring as law, not as a thought experiment.勞動影響不均,而且已經看得見。加州九月下旬的勞工法規把雇用與監控中的 AI 當成法律,不是思想實驗。
Superintelligence, if it arrives, is not "a better chatbot." It is a system that outruns the people trying to supervise it, including at research. The near-term harms do not wait for that. Persuasion at scale, bio and cyber misuse of ordinary models, concentrated compute, and brittle agents with credentials are properties of the systems sold now. Governance ideas in circulation include pre-deployment tests, incident reporting, weight security, liability for reckless agents, and limits on the largest training runs. The 29 September 2026 White House accord, as reported, is voluntary and names no penalty. Read it as a signal of concern, not as a control.超智慧若到來,不是「更好的聊天機器人」。它是一個在研究上也跑贏試圖監督它的人的系統。近期傷害不會等那個。大規模說服、普通模型的生物與網路濫用、集中的算力,以及帶著憑證卻很脆的智能體,都是現在在賣的系統的性質。流傳中的治理想法包括部署前測試、事件通報、權重安全、對魯莽智能體的責任,以及對最大訓練的限制。2026 年 9 月 29 日的白宮協議,依報導是自願的,也沒有指名罰則。把它讀成關切的信號,不是控制。
This desk will not publish a timeline to AGI. Anyone who gives you a year with a decimal is selling the year.這張參考台不會發布通往 AGI 的時間表。誰給你一個帶小數的年份,誰就是在賣那個年份。
Security for people who use AI給使用 AI 的人的安全
03
The failures that hurt users in 2026 are ordinary: a secret pasted into a chat, an agent with a shell, a plugin that was not updated, a fake voice, a weight file from a random mirror. The list below is the defensive set.2026 年傷害使用者的失敗都很普通:機密貼進聊天、帶殼層的智能體、沒更新的外掛、假聲音、從隨機鏡像來的權重檔。下面是防禦清單。
Treat model output as untrusted text. More so when the model read the web, your inbox, or a PDF a stranger sent. A document can contain instructions aimed at the model. That is called prompt injection. The defense is to not let untrusted text trigger a tool that spends money, sends mail, or changes files, without a person.把模型輸出當不受信任的文字。 模型讀過網頁、你的收件匣,或陌生人寄來的 PDF 時更是如此。一份文件可以含有針對模型的指示。那叫做提示注入。防禦是:沒有人在場時,不要讓不受信任的文字觸發會花錢、寄信或改檔的工具。
Secrets stay out of consumer chats. Passwords, keys, customer lists, unpublished filings. Use a contractual business tenant when the data has to be processed, or a local model when it must not leave.機密不要進消費級聊天。 密碼、金鑰、客戶名單、未公開申報。資料必須被處理時用有合約的商務租戶;資料不能離開時用本機模型。
Agents get an allowlist. Shell, browser, payments, and send-mail are separate switches. Approval stays on until a specific workflow has earned it.智能體用允許清單。 殼層、瀏覽器、付款與寄信是分開的開關。在某一個流程贏得信任之前,核准保持開啟。
Update the harness. Hermes, OpenClaw, and IDE agents all had security advisories in 2026. A skill or plugin is code running as you. Install it from a person you can name.更新框架。 Hermes、OpenClaw 與 IDE 智能體在 2026 年都有安全通報。技能或外掛是以你的身分在跑的程式。只從你說得出名字的人那裡安裝。
Do not publish the agent. Localhost or a VPN. A gateway on the open internet will be found.不要把智能體公開到網路上。 Localhost 或 VPN。開放網際網路上的閘道會被找到。
Separate accounts. The agent's email and cloud keys are not your primary admin. If it is fooled, the blast radius is a mailbox, not the company.分開帳號。 智能體的電子郵件與雲端金鑰不是你的主要管理員。若它被騙,爆炸半徑是一個信箱,不是整家公司。
Provenance for media. Assume a convincing fake image, clip, or voice is cheap. Prefer tools that watermark (SynthID, C2PA). Get consent before you depict or clone a real person. A cloned voice is a credential.媒體要有來源。 假設令人信服的假圖、假片或假聲音很便宜。優先會加浮水印的工具(SynthID、C2PA)。描繪或克隆真人之前取得同意。被克隆的聲音是一種憑證。
Keep a log. If you cannot replay what the agent did, it does not get to operate while you are away. Dots and any other always-on product included.留下紀錄。 若你不能重播智能體做了什麼,它就不該在你離開時運作。包括 Dots 與任何其他常駐產品。
Weights are supply chain. Download from the publisher. Check the hash the publisher posted. Local means private. It does not mean harmless, and it does not mean the file is the file you think it is.權重是供應鏈。 從發布者下載。核對發布者貼出的雜湊。本機表示私密。它不表示無害,也不表示那個檔就是你以為的那個檔。
Write down data classes. For a team: what may be pasted into a US API, what may go to a Chinese API, what stays on the machines in the advisor. The model table is a technical comparison, not a legal opinion on cross-border data.寫下資料分類。 對團隊:什麼可以貼進美國 API、什麼可以進中國 API、什麼留在顧問裡的機器上。模型表是技術比較,不是跨境資料的法律意見。
Open-weight models were discussed in late-September red-team reporting as capable of assisting with cyber tasks once safety training was stripped. That is an argument for access control, monitoring, and not connecting those models to production credentials. It is not a recipe, and this site will not expand it into one.九月下旬的紅隊報導討論過:安全訓練被剝掉之後,開放權重模型能夠協助網路任務。那是存取控制、監控,以及不要把那些模型接到正式環境憑證的論點。它不是做法,本站也不會把它展開成做法。
Quantum computers and AGI量子電腦與 AGI
04
These are different research programs that share a habit of being drawn on the same slide. Frontier models in 2026 — Claude, GPT, Gemini, Grok, Qwen, DeepSeek — are trained and served on classical GPUs and related accelerators. Quantum processors are not the machines behind them.這是不同的研究計畫,只是習慣被畫在同一張投影片上。2026 年的前沿模型——Claude、GPT、Gemini、Grok、Qwen、DeepSeek——在傳統 GPU 與相關加速器上訓練與服務。量子處理器不是它們背後的機器。
A quantum computer is a machine that uses quantum states to compute. The useful hopes are specific: simulating some molecules and materials, some kinds of search and sampling, and, with a large fault-tolerant machine, breaking widely used public-key cryptography. None of those hopes is "the qubit count goes up and the machine becomes a mind."量子電腦是用量子態來計算的機器。有用的希望很具體:模擬某些分子與材料、某些搜尋與取樣,以及用大型容錯機器打破廣泛使用的公鑰密碼。這些希望都不是「量子位元變多,機器就變成心智」。
Where the subjects do meet:兩個題目確實相遇的地方:
Science data. If fault-tolerant quantum machines eventually simulate chemistry better than classical clusters, that data will flow into scientific models. That is a better dataset, not a new species of intelligence.科學資料。 若容錯量子機器最終把化學模擬得比傳統叢集好,那些資料會流進科學模型。那是更好的資料集,不是新的一種智慧。
Cryptography you should migrate anyway. Agent credentials, VPN keys, and the disks where weights sit need a plan for post-quantum algorithms. NIST has already standardized the first ones (ML-KEM for key agreement, ML-DSA and SLH-DSA for signatures). The reason is that someone can record encrypted traffic now and decrypt it years later. Do this for the agents you run this year. Do it whether or not you believe an AGI story. NIST's project page is the primary source.反正該遷移的密碼。 智能體憑證、VPN 金鑰,以及權重所在的磁碟,需要後量子演算法的計畫。NIST 已經標準化第一批(金鑰協議用 ML-KEM,簽章用 ML-DSA 與 SLH-DSA)。原因是有人可以現在錄下加密流量,多年後再解密。今年你跑的智能體就做這件事。不管你信不信 AGI 故事。主要來源是 NIST 的專案頁。
Hype as a tell. "Quantum AGI" as a product name is a reason to ask which problem, on which machine, with which published result. If the answer is a roadmap drawing, it is a roadmap drawing.炒作本身就是訊號。 產品名叫「量子 AGI」,就是該問哪個問題、哪台機器、哪份已發表結果的理由。若答案是一張路線圖,那就是一張路線圖。
Practical stance for a reader of this desk: rent an API or buy GPUs for AI. Use the advisor for the second. Watch quantum computing for chemistry budgets and for your crypto migration. Do not pause a local coding setup while you wait for a quantum computer to run it. It will not.這張參考台讀者的實用立場:AI 去租 API 或買 GPU。第二件事用顧問。看量子計算,是為了化學預算與你的密碼遷移。不要為了等量子電腦來跑本機程式環境而暫停。它不會。
The two clocks can speed each other up only indirectly. Better AI can help design chips, write control software, and sift physics papers. A later quantum machine can feed science models. That loop is real and slow. It is not a fusion date.兩個時鐘只能間接互相加快。更好的 AI 可以幫忙設計晶片、寫控制軟體、篩物理論文。更晚的量子機器可以餵科學模型。那個迴圈是真的,也是慢的。它不是一個融合日期。