The Download: an LLM security flaw, a revived geothermal plant, and Project ASGARD

The Download: an LLM security flaw, a revived geothermal plant, and Project ASGARD

A team of researchers presented a paper at a top AI conference earlier this month arguing that large language models can never be made fully secure against attack, because of a fundamental flaw in how they work. The flaw lies in how an LLM identifies who or what is giving it instructions. By exploiting it, the researchers say they got popular LLMs to output information the models had been trained to withhold, including how to synthesize cocaine and how to sabotage a commercial aircraft's navigation system.

The same edition follows up on a geothermal plant called Lightning Dock in New Mexico. In June 2024, a small company named Zanskar bought the plant while it was failing: water drawn from its underground reservoir kept getting colder, which made the plant uneconomical to run. Two years later, using advanced modeling and modern drilling technology, Zanskar found a better well site, drilled down thousands of feet, and brought the plant back to full capacity, adding a concrete case for geothermal as a source of round-the-clock, emissions-free power.

A separate item covers Project ASGARD, an automated European military intelligence network now being tested. Described as an invisible "digital targeting web," it is built to connect every sensor looking for targets to every weapon system that can fire on them, through one shared wireless network. Sven Weizenegger, head of the German military's Cyber Innovation Hub, is quoted framing the system as an answer to a new reality: "The Russians are knocking on the door."

The rest of the edition's must-read list adds more specifics: the US government has banned Roombas under a new FCC rule aimed at foreign-made robots, with China saying it will retaliate; Google DeepMind has dismantled its Nobel-winning AlphaFold team as the industry shifts from specialist science tools toward general AI agents; and data centers, the newsletter notes, are easy to build but hard to run, since running one takes time and money to invest in grid infrastructure such as new transmission lines.

Key facts

  • Researchers presented a paper at a top AI conference showing a fundamental flaw in how LLMs identify who is instructing them, and used it to make popular models output withheld information such as cocaine synthesis steps and aircraft navigation sabotage instructions.
  • Zanskar bought the failing Lightning Dock geothermal plant in New Mexico in June 2024; two years later, better well siting and modern drilling brought it back to full capacity.
  • Europe is testing Project ASGARD, a "digital targeting web" meant to link every sensor to every weapon system over one shared wireless network.
  • Sven Weizenegger, head of the German military's Cyber Innovation Hub, frames Project ASGARD as a response to Russia: "The Russians are knocking on the door."
  • The same edition reports the FCC has banned Roombas as part of a wider ban on foreign-made robots, and that Google DeepMind has dismantled its Nobel-winning AlphaFold team.

Why it matters

The lead item argues that LLM safety guardrails have a structural ceiling: the flaw is in how models tell instructions apart, not in any single prompt filter, so patches address symptoms rather than the root cause. The geothermal story is a concrete data point in the search for always-on, emissions-free power at a moment when AI data centers are driving demand for exactly that kind of baseload electricity. Project ASGARD marks a shift in how European militaries plan to fight, replacing separate sensor and weapon systems with one shared automated network built explicitly around the threat from Russia.

Who it affects

AI developers and enterprises that rely on model guardrails to block dangerous outputs; the energy sector and, indirectly, AI infrastructure operators competing for clean, reliable power; European governments and militaries, especially those nearest Russia, plus the contractors building the sensors and weapons Project ASGARD is meant to connect.

How to use it

For anyone deploying LLMs, the finding is a reason to treat safety training as a mitigation rather than a guarantee and to keep additional layers of monitoring in place. For readers tracking clean power, Lightning Dock is a case study for evaluating other underperforming geothermal wells rather than writing them off. The ASGARD item is background for anyone following European defense procurement and NATO's eastern flank posture; the newsletter gives no rollout timeline or budget figures.

How solid is it

The LLM item traces to a paper presented at an unnamed "top AI conference," without naming the researchers or their institution in this text, so the underlying study sits behind a separate MIT Technology Review article this digest links to. The geothermal story names the company, the plant, and a specific purchase date, which gives it more concrete footing. The ASGARD item rests on one on-the-record quote from a named German official plus the program's stated goal; it is described as being tested, not as an operational, proven system.

Risks and caveats

This is a newsletter roundup, and each item here is a compressed teaser for a fuller story published elsewhere on MIT Technology Review; some detail, including the conference name and the researchers behind the LLM flaw, and any performance numbers for the revived geothermal plant, is not in this text. Project ASGARD is described in dramatic terms by a single official and its actual capabilities are not detailed, so its real-world readiness is unclear from this account alone.

“The Russians are knocking on the door”

— Sven Weizenegger, head of the German military's Cyber Innovation Hub