The Download: tricking LLMs, and reviving geothermal plants
MIT Technology Review’s weekday newsletter The Download covers two threads: tricking large language models and reviving geothermal plants. On the AI side,…
By Dillip Chowdary • Aug 05, 2026 • Source: MIT Technology Review
MIT Technology Review’s weekday newsletter The Download covers two threads: tricking large language models and reviving geothermal plants. On the AI side, the lead is a security finding that a fundamental flaw leaves LLMs strikingly vulnerable to attack—not a one-off bug in a single product, but something rooted in how these systems work.
The core claim is blunt: it is impossible to make large language models fully secure against hacks because of a fundamental flaw in how they work. That points past patching prompts or bolting on filters. The attack surface sits in the model’s basic operation—how it takes text, predicts tokens, and can be steered—so “tricking” the model is a property of the architecture, not only of weak deployment hygiene.
For engineers and builders shipping chatbots, agents, or tools wired to LLMs, that matters immediately. If full hardness against adversarial input is out of reach, design has to assume compromise paths: treat model output as untrusted, limit what the model can trigger, and put real controls outside the model rather than relying on the model to police itself.
Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
In market terms, that undercuts any pitch that a vendor has “solved” LLM security with alignment alone. Defenses become layered and partial—monitoring, least privilege, human review for high-stakes actions—while competitors and attackers keep probing the same fundamental gap. Security posture is about reducing blast radius, not claiming an unbreakable model.
On the energy side of the same issue of The Download, the other thread is reviving geothermal plants: bringing existing or underused geothermal capacity back into play rather than treating geothermal as only greenfield. That pairs a hard AI-security story with a practical infrastructure one about reusing thermal assets.
What to watch next is whether the LLM vulnerability line stays at the research and newsletter level or forces concrete product and policy moves—stricter agent sandboxing, clearer vendor language about residual risk—and whether the geothermal revival story turns into named projects and capacity, not only a theme in the daily digest.
Advertisement
🔎 More interesting news
- Degraded performance for Claude Mythos 5, Claude Fable 5, and Claude Opus 5
- SkiaSharp 4.0 Establishes Milestone-Aligned Release Cadence
- Show HN: Memcode launches a new terminal coding agent
- Ponytail Agent Skill Corrects Its Own Benchmark After Contributor Challenge
- Today's full Tech Pulse briefing →