Build1 distinct publisher3 min readPublished
The lab named tamper resistance an open question 40 days after Inkling's weights shipped. The award is platform compute, priced by the grantor and spendable only on the approved study.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
Tinker trains LoRA adapters rather than updating every parameter, which is how the platform shares computing capacity across jobs [13]. That detail sets the boundary of what a grant-funded tamper-resistance study can actually measure: cheap adapter training, on hosted infrastructure, with scheduled check-ins from the host [9]. The threat described in the same announcement is wider. Anyone holding the weights can remove behavioral safeguards or train on hazardous material [6], using full fine-tuning, off-platform, with nobody metering it. Inkling activates 41 billion of its 975 billion parameters [4], about 4.2 percent [18], so it is cheap to serve and cheap to modify for the funded researcher and the unfunded one alike.
Then there is the denomination. Because the credit is measured at Tinker's current rates and locked to one approved proposal [8], the grantor sets how much compute the headline figure converts into, and can reset it. The engagement runs up to six months [9] while unused credit lives twelve [8], leaving a six-month tail [19] that can only be spent on a study already finished. The ceiling is also per participant, and neither the number of awards nor the total budget appears on the cited pages [12], so $50,000 describes one researcher's maximum and tells you nothing about the program's size.
Forty days separated the larger model's release from the grant call [16]. Applications run for 32 days [17], with review promised within a week of the September 25 deadline [10], and selected work continuing for as long as half a year [9]. The weights stay public through all of it. Thinking Machines' own open-weight safety framework says downloadable models widen access while creating irreversible misuse risks [14], which is a reasonable argument for having tamper-resistance results in hand before publishing weights rather than commissioning them afterwards.
What the topic list concedes is more interesting than the money. Putting tamper-resistant safeguards next to reward hacking, alignment failures and the measurement of how risk changes after fine-tuning [5] locates the unsolved problem in customization, not in how the model behaves the day it ships. Murati's stated position is that a small number of labs should not permanently fix one system's behavior for everyone, and that organizations should keep reshaping models with their own knowledge [21]; Tinker is the commercial form of that argument, handing researchers control of data, loss functions and training loops while the lab runs the infrastructure [13]. The open question is whether safeguards can be made to survive the modification the product exists to sell. Paying in access to that same modification infrastructure [7] is efficient on both sides of the ledger: the lab settles in capacity it already operates, and it buys precisely the evidence a customization-first vendor will need to show.
Selection weighs relevance, feasibility, construct validity and generalizability [11], which reads like a lab that wants small, repeatable results it can cite. Construct validity is the one to watch. A study that only stresses adapters on Tinker has measured the resistance of a safeguard to the polite attack.
Ranked by verification strength, evidence, and original report placement.
Mira Murati's Thinking Machines Lab is offering up to $50,000 in Tinker credits per participant for outside research into the safety of its open-weight Inkling models.
The grant announcement was made on August 24 and summarized the following day by Aligned News.
The 975-billion-parameter Inkling was released on July 15, and the smaller 276-billion-parameter Inkling-Small followed on July 30.
Inkling is a mixture-of-experts model with 41 billion active parameters and a context window of up to 1 million tokens; Inkling-Small has 12 billion active parameters and the same maximum context length. Both process text, images and audio and are available for fine-tuning through Tinker.
The program's announcement lists work on defensive capability, tamper-resistant safeguards, alignment failures, reward hacking, and measuring how risk changes after fine-tuning, and invites proposals outside those categories.
Releasing weights also lets developers remove behavioral safeguards or train models on hazardous material.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Documented program terms, single-chain sourcing
Award ceiling, credit restrictions, expiry, collaboration length, deadline, selection criteria, eligibility and model specifications are all specific and attributed to the grantor's announcement, application and terms pages. But the entire chain is one outlet summarizing another outlet's summary of the lab's own documents, with no independent verification, no named applicant or reviewer, and the article itself flags that participant count and budget are undisclosed.
Weights shipped, program unstaffed
Two open-weight models are demonstrably released and an earlier grant tier has named recipients at Stanford and Carnegie Mellon, so the platform has real uptake. The safety program itself shows no adoption yet: the application deadline had not passed as described, no participants are named, no award count or budget is disclosed, and no research output exists.
Dollar headline, credit reality
The '$50,000' framing reads as research funding but is platform credit priced by the grantor, restricted to one approved study, expiring in 12 months and never convertible to cash; participant count and total budget are withheld, so the program's aggregate commitment is unknown. The gap is moderate rather than severe because the reporting itself discloses the restriction, the undisclosed scale and the structural tension that the grant pays in the very infrastructure that eases safeguard removal.
Grantor-funded study of grantor's own risk
Every material fact originates with the party being assessed. The lab sets the credit's price, restricts its use to work it approves, receives a perpetual, sublicensable license to the resulting work including for product improvement, requires written approval before publication of work referencing its materials, and gains marketing and distribution value for Tinker - which the reporting frames as the third grant initiative tied to the platform. The reporting outlet is one step further removed, relaying a third party's summary.
Internally consistent, externally unverified
The factual spine is specific, quantified and internally consistent, and the article marks its own gaps. Confidence is held near the middle because a single publisher on a single relayed source carries no corroboration, the cited dates lack years in the reporting, and the program's substantive question - whether safeguards survive fine-tuning - has no results attached.
build
1.5% of Hugging Face repos take 99.2% of downloads, and the ceiling is Chinese1 distinct publisher
invest
Meta hires another ChatGPT alumnus, and the whole industry pays the retention bill1 distinct publisher
security
Akrites switches on in September with 20-odd members and a one-to-10 engineer donation band1 distinct publisher
build
AI code has sat at 55% secure for two years. Waiting for a better model is not a plan.1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 25, 2026