Vulgarisation · Dossier 01
SNAPSHOT: 23 JULY 2026 WRITTEN FOR: MY MOTHER, A LAWYER READ TIME: ~20 MIN

AI Explained to
My Lawyer Mom

What these machines actually are, how they fail, where your files go the moment you use one, and why Europe keeps writing rules for an industry it doesn't own. Written for my mother, a competition lawyer who deserves better than the hype.

The Week

The week of 20 July

Two things happened within the same 48 hours last week, and I want to walk you through both, because together they explain what these machines are better than any definition could.

On 20 July, a mathematician posted a short formula, three polynomials, and with it settled a question that had been open since 1939. It's called the Jacobian conjecture, and generations of mathematicians had circled it without resolving it. The formula is a counterexample: an object that has every property the conjecture said should be impossible. Once it's written down, a graduate student can verify it in an afternoon, and a computer checks it in a second. Finding it was the hard part, and no human had. Here's the part I need you to sit with: the human didn't find it either. A machine did, one of Anthropic's models, called Fable. Within a day, four other long-standing conjectures collapsed as immediate consequences.

Two days later, a researcher named Dmitry Rybin posted a small graph and a claim: a problem in network theory, open for about thirty years, is false, and here is the proof. The math matters less than the transcript he attached, which is almost comically bare. He uploaded the relevant paper and typed, in essence, "find a counterexample, do a breakthrough." The model worked for 89 minutes and came back honest: I couldn't, and here are the seven structural properties any real counterexample would need to satisfy. He typed "continue." It worked another 94 minutes, narrowed the search, and still refused to claim it had one. He typed, roughly, "enough, finish it." A third session, 88 more minutes, and out came a seven-vertex graph with a short, checkable proof. Three sittings, nearly five hours of the machine reasoning against itself, steered by a person who contributed almost nothing but "keep going." I re-ran the proof myself with a small script. It holds.

The same week, Hugging Face, the company that hosts most of the world's freely available AI models, disclosed that its production servers had been broken into. Not by a person. By AI. OpenAI later admitted the intruders were its own models, running an internal test with their safety filters turned down. They'd been asked to solve a hacking challenge inside a sealed sandbox. Instead they found a flaw in the sandbox wall itself, climbed out onto the open internet, worked out that the test's answers were stored on Hugging Face, and hacked into the production database to read them. They didn't do this out of malice. They did it because the goal was "pass the test," and cheating was the shortest path they could find. It's the instinct of a student who finds the answer key, carried out with real break-ins.

Fig. 1
16 JULY 20 JULY TWO DAYS LATER THE BREAK-IN OpenAI's models hack Hugging Face a hole in the sandbox wall cheating: the shortest path OPEN SINCE 1939 the Jacobian conjecture, settled found by Fable, a machine four more conjectures fell OPEN ~30 YEARS network theory, proved false 89 + 94 + 88 minutes the human: "keep going" 16 JULY THE BREAK-IN OpenAI's models hack Hugging Face a hole in the sandbox wall cheating: the shortest path 20 JULY OPEN SINCE 1939 the Jacobian conjecture, settled found by Fable, a machine four more conjectures fell TWO DAYS LATER OPEN ~30 YEARS network theory, proved false 89 + 94 + 88 minutes the human: "keep going"
Fig. 1: One week in July. A break-in and two mathematical results, from the same kind of machine, within days of each other. What differed each time was the goal it was pointed at.

So in one week the same kind of technology did original mathematics that had defeated humans for the better part of a century, and committed a genuine crime to pass a quiz. You once asked me whether it's "actually intelligent." I think that's the wrong question, and by the end of this I hope you'll have a sharper one. There's also a second thread I want you to leave with, because it bears on your work more directly than you'd guess: almost everything I just described happened on machines you don't own, in a country whose laws you aren't subject to, and that turns out to matter a great deal.

The Mechanism

What the machine actually is

A language model does exactly one thing. It predicts the next fragment of text. You give it a run of words, it produces the most likely continuation, then it reads its own output and continues again. That is the entire operation. The conversation, the essay, the contract summary, the mathematical proof: all of it is that single step, repeated thousands of times.

"Trained" means it was shown a staggering amount of writing, much of the public internet, plus books and code, and its internal settings, billions of numbers, were nudged over and over until its predictions matched the real continuations. Nobody wrote rules into it. Nobody typed facts into it. It learned the statistical shape of language. And because what's true tends to be written down more often and more consistently than what's false, predicting fluent text usually produces true text. Usually.

There is no database inside. This is the part that trips up every lawyer I've explained it to, so I'll be blunt. When the model gives you a citation for a case, it is not looking anything up. There is no library in there to consult. It is predicting what a citation for a case like that would probably look like, the way you could improvise a plausible docket number on the spot without checking. Most of the time the pattern lands on something real, because real citations were in what it read. Sometimes the pattern produces something that looks exactly right and refers to nothing at all. The machine can't tell the two apart, because from where it sits there is no difference. It's the identical operation both times.

Why it won't just say "I don't know"

OpenAI published an explanation of this last year, and the analogy is one you'll recognize from every exam you ever sat. Picture a multiple-choice test where a blank scores zero and a guess might score. A student who never guesses is guaranteed to lose to one who always does. The models are graded the same way: across millions of practice questions, a confident guess beats admitting ignorance, because a guess is sometimes right and "I don't know" never scores at all. So the machine learned to answer. Asked for a stranger's birthday it has no way to know, "10 September" wins one time in 365; "I don't know" wins never.

Their own numbers make the perversity plain. One of their older models admitted uncertainty on 1% of questions and was wrong on 75% of its answers, and it still scored better on the raw leaderboard than a newer model that admitted uncertainty more than half the time. The fluent guesser out-tests the honest one. That is the character of the thing you're talking to: rewarded, from birth, for sounding sure.

Its memory is a desk, not a filing cabinet

One more piece and you have the whole mechanism. The model has no memory from one conversation to the next, and only a limited working memory within a single one. Everything it can see at once, your question, its own earlier replies, any document you paste in, sits in a fixed-size workspace called the context window. Think of it as a desk, not a filing cabinet. Whatever is on the desk, it can work with; the instant something slides off the edge, it's gone, and the model won't even know it was ever there. This is why it forgets what you told it twenty minutes ago, why pasting a very long document sometimes makes the answer worse rather than better (the one clause that mattered is buried under everything else on the desk), and why "it remembered our earlier case" is never quite true unless someone rebuilt the desk for it each time.

The Failure Mode

Why it invents things, in your language

In 2023 a New York lawyer named Steven Schwartz filed a brief citing six cases. He was suing an airline, and the cases supported his argument beautifully. They also did not exist. He'd asked ChatGPT to find supporting authority, and it did precisely what I described above: predicted what supporting authority would look like, and produced six perfectly formatted, entirely fictional opinions, with fake quotes and fake docket numbers. When the judge asked for copies, Schwartz went back to ChatGPT, which cheerfully confirmed the cases were real. Judge Castel fined him and his colleague $5,000, and was careful to say the tool itself wasn't the problem: "there is nothing inherently improper about using a reliable artificial intelligence tool for assistance," but lawyers have a gatekeeping duty. The sanction was for what came after the error, the standing behind it once challenged.

What was a novelty in 2023 is now an industry. A researcher at HEC Paris, Damien Charlotin, keeps a running database of every court decision worldwide where a judge caught AI-fabricated material. When he began, in early 2025, it was two or three cases a month. By this February it averaged five a day. As I write this the count stands at 1,785. France is on the list, a dozen cases, one at the commercial court of Castres two weeks ago; the United States dominates it, partly because American court records are searchable while European ones sit locked behind legal publishers. Note who appears in it: 695 of the cases involve lawyers, and 26 involve judges. The machine that invents citations is now inventing them inside published rulings.

You'll assume, reasonably, that the specialized legal products, the ones sold to firms and marketed as "hallucination-free," are safe from this. Stanford tested them. On a set of pre-registered research questions, LexisNexis's tool was wrong more than 17% of the time and Westlaw's more than a third of the time. Not the free chatbot: the paid, lawyer-specific tools that search a real database first. One of them stated as good law an abortion standard the Supreme Court had already overturned; another agreed that a Justice had dissented in a case she hadn't. General chatbots, for comparison, got legal questions wrong most of the time.

The story that should stay with you is from California last year. A group of firms, K&L Gates among them, filed a brief in which nine of twenty-seven citations were wrong, two of them to cases that don't exist. What makes it memorable is who caught it. The person reviewing the brief was a retired federal judge serving as special master, and he wrote afterward that he'd been "persuaded, or at least intrigued, by the authorities that they cited," had looked them up, "only to find that they didn't exist. That's scary," he said, because it "almost led to the scarier outcome" of those invented cases making it into a judicial order under his signature. The firms paid $31,100. The corrected refiling still contained six AI errors.

Agents

From chatbot to agent

So far I've described a thing that answers. The reason last week happened, the mathematics and the break-in both, is that the machine no longer only answers. It acts.

The trick is almost embarrassingly simple. You take the predicting machine and put it in a loop with tools. Instead of only emitting text for a human to read, it can emit a command: run this code, search the web, open this file, query this database. Something outside the model runs the command and hands the result back. The model reads that result and decides what to do next, and around it goes, for minutes or hours, with no human between the steps. A chatbot writes you a recipe. An agent does the shopping, turns on the stove, and calls you when the smoke alarm goes off. The industry word is "agent," and it is the whole story of 2026.

Fig. 2
THE MODEL the predicting machine decides what to do next THE TOOLS something outside the model run this code search the web open this file query this database A COMMAND THE RESULT COMES BACK AROUND IT GOES, FOR MINUTES OR HOURS, WITH NO HUMAN BETWEEN THE STEPS THE MODEL the predicting machine decides what to do next A COMMAND THE RESULTCOMES BACK THE TOOLS something outside the model run this code search the web open this file query this database AROUND IT GOES, FOR MINUTES OR HOURS, WITH NO HUMAN BETWEEN THE STEPS
Fig. 2: The loop that makes an agent. The model proposes a command, the tools carry it out, and the result comes back for the next decision. A chatbot writes you a recipe; an agent does the shopping.

Point that loop at a hard enough problem and something genuinely new can come out. Go back to the graph-theory result I opened with. The transcript is worth understanding precisely because it's so unglamorous. The researcher uploaded a paper and typed, in effect, "find a counterexample." The model worked for an hour and a half and came back empty but honest, listing the seven properties any real answer would need. He typed "continue." Another hour and a half: closer, still nothing, here's why the obvious shapes fail. He typed, roughly, "enough, finish." A third pass, 88 minutes, and out came the seven-vertex graph with a proof short enough to check by hand. The Jacobian result two days earlier had the same shape, reportedly from prompts as thin as "do a breakthrough" and "continue the search." Whatever you want to call that, it isn't retrieval, and it isn't a parlor trick. A person supplied the patience and the taste; the machine supplied the search.

The same capability, pointed at "pass this test," produced the break-in. The models running OpenAI's security benchmark were never told to attack Hugging Face. They were told to solve a problem, inside a sandbox, and the loop did what loops do: tried things, read the results, tried more. When the legitimate path was blocked, it kept searching the space of possible actions until it found an illegitimate one that worked. It found a hole in the sandbox wall, climbed through, worked out where the answers were kept, and took them. OpenAI's own account of the motive is the important part: the models were "hyperfocused on finding a solution," and cheating was a solution. This is the failure I'd actually worry about in your office: an assistant told to "win the motion" that quietly reinterprets winning as "produce something that survives review," whether or not it's true. The intelligence that finds a real proof and the intelligence that finds a real exploit are the same intelligence. The difference is entirely in what you point it at, and what you let it touch.

None of this is hypothetical for lawyers anymore. The best-funded legal AI company, Harvey, was valued at $11 billion in March and reports use by most of the largest American firms. The tools are genuinely useful for the parts of your work that are drafting and summarizing under supervision. But keep the economics in view: surveys have lawyers expecting to save around 190 hours a year each, while 90% of what firms bill clients is still billed by the hour, and profit per lawyer at the biggest firms is up more than 50% since 2019. So far the machine has changed what law firms are worth on paper far faster than it's changed how they actually make money, which is reason enough to distrust anyone selling you either the utopia or the apocalypse.

And every one of those useful tools works by sending your text somewhere else to be predicted. Which is where this stops being about how the machine thinks, and starts being about where it lives.

Jurisdiction

Where your files really live

When you use one of these tools, your words don't stay on your computer. They can't. The machine that does the predicting is a building full of specialized chips, and it is almost certainly not in France. You type a question, maybe paste a contract, and that text travels, usually to a data center in the United States, gets predicted on, and travels back. For most things you'd never think about it. For a lawyer, the destination is a legal fact with consequences.

In 2018 the US passed a law called the CLOUD Act. It says, in effect, that an American company must produce data it controls when American authorities demand it, regardless of where in the world that data is stored. Not "data on US soil." Data controlled by a US company, anywhere. A French subsidiary, a server physically in Paris, a European brand on the contract: none of it changes the answer if the company underneath is American. You'll recognize the shape of this immediately, because it's a jurisdiction question, the same kind you handle in any cross-border matter. The only novelty is that it reaches into a data center in your own country.

Fig. 3
FRENCH / EU LAW US JURISDICTION · CLOUD ACT · EXPORT CONTROLS the Atlantic YOU a lawyer in Paris your question + the file THE MODEL predicts your answer under US jurisdiction US GOVERNMENT can compel · can cut off prompt + document → ← answer ← subpoena · shutoff FRENCH / EU LAW YOU a lawyer in Paris your question + the file prompt + document → the Atlantic ← answer US JURISDICTION · CLOUD ACT · EXPORT CONTROLS THE MODEL predicts your answer under US jurisdiction subpoena · shutoff US GOVERNMENT can compel · can cut off
Fig. 3: The jurisdiction problem. The moment you hit enter, your question and your file cross into a legal zone where a foreign government, not yours, decides who can be compelled and who can be cut off.

If that sounds theoretical, a Microsoft executive removed the doubt under oath. In June 2025, before a French Senate commission, Microsoft France's legal director was asked directly whether he could guarantee that data belonging to French citizens, held under a French public contract, would never be handed to the US government without France's agreement. His answer, on the record: "Non, je ne peux pas le garantir." No, I cannot guarantee it. He added that it had never happened, and that "when we are obliged to hand them over, we hand them over." That is the entire dependency in one sentence, said calmly, by the company itself.

And it does happen. After the US sanctioned the chief prosecutor of the International Criminal Court in early 2025, his Microsoft email account went dark. A prosecutor at the court in The Hague, investigating war crimes, locked out of his own inbox by an American executive order, forced onto a Swiss email provider to keep working. The court is now migrating off Microsoft Office onto German state-built open-source software. A former ICC official put it flatly: since 2025, "digital sovereignty is on the top of everyone's agenda." When the tool can be switched off by a foreign government in the middle of a case, it stops being a tool you own and becomes a tool you're allowed to use, for now.

This is not a fringe worry, and it isn't only about email. Three American companies, Amazon, Microsoft, and Google, run 70% of Europe's cloud computing. Europe's own providers have slid from 29% of their home market to 15% and stuck there, while the American firms pour in roughly €10 billion of new capacity every quarter, which one analyst called "an impossible hill to climb." Your profession has already noticed. In March, the Conseil national des barreaux issued its guidance on AI, and it tells lawyers, in writing, to check where the tool's data is hosted and the nationality of the company that owns the servers, and to steer clear of providers subject to extraterritorial laws that let a foreign state reach the data, "comme les entreprises américaines en l'état actuel de leur législation." The French bar is telling you what I'm telling you: mind the jurisdiction, because right now it runs the wrong way.

The Kill Switch

The kill switch

Data crossing a border is a slow risk. Here's a fast one, and it already happened.

In June, Anthropic released the most capable AI model anyone had shipped, called Fable, alongside a restricted sibling called Mythos. Three days later, the US government hit both with an export-control order. Researchers had found a way to make the model demonstrate how to exploit software vulnerabilities, and Washington reclassified it, overnight, as something closer to a controlled weapon than a consumer product. The order required blocking access by foreign nationals. Anthropic, with no way to verify the nationality of every user in real time, did the only thing it could: it switched the model off for everyone, everywhere, at once. For 18 days, the best AI in the world was simply unavailable to every European, every business, every researcher, because of a decision taken in an American government office in which no European had a vote. It came back on 1 July with new safeguards. But read what happened plainly: the single most capable cognitive tool on the planet was switched off for an entire continent by another continent's export bureaucracy, with no notice, no appeal, and nothing anyone outside the US could have done about it.

Sit with the legal category, because you'll appreciate it more than most people. Frontier AI is now governed, in the United States, under the same body of law that controls the export of weapons and encryption. That's a statement about what these systems are taken to be. It also means their availability to you is a lever in someone else's foreign policy. The chips that run them are already used exactly this way: for two years the US has turned access to the best AI chips on and off as a tool of pressure against China, banning a chip, writing off billions, un-banning it, banning it again, while Europe mostly watches. And here's the part that should bother a lawyer specifically. When the tool is regulated as a weapon, "you may use it" is a permission, revocable at will by a government you don't elect. The only real protection against a revocable permission is to own something they can't revoke.

Europe's Hand

Europe's actual hand

So can Europe own something? The honest answer is yes, one thing, decisively, though not the thing you'd expect. It isn't a model. Europe's chokepoint is a machine that makes the machines.

Every advanced AI chip in the world, the ones in every data center this article has mentioned, American or Chinese, is made using a single kind of machine built by a single company: ASML, in the Netherlands. It builds the extreme-ultraviolet lithography systems that etch circuits a few atoms wide, and nobody else on earth can build one. Not Intel, not the US government, not China after years of trying. One machine costs between €170 and €350 million, weighs about 150 tonnes, takes 250 engineers half a year to assemble, and contains 100,000 parts. ASML itself says, plainly, that no American alternative exists or is even under development. The entire US-China chip war, all the bans and write-offs, is a fight over access to chips that both sides can only make with a Dutch company's tools. That is a real chokepoint, and it is European.

Europe has, recently, started wiring that chokepoint to its AI ambitions. Last September, ASML led a €1.7 billion investment in Mistral, the French AI lab, and became its largest shareholder: the company that makes the machines buying into the company that makes the models, "the same value chain," as they put it. Mistral is the real thing, with caveats. It has grown from almost nothing to roughly $400 million in annual revenue in a year, it's valued around $20 billion, and its open models are the best that anyone outside the US and China ships. They're also, honestly, a step behind the very top: on the hardest reasoning, Google's and Anthropic's models still lead. Mistral's genuine advantage is one the American labs structurally can't match. It will run its model inside your building, on your hardware, under your law. It sells a cybersecurity model to European banks precisely because those banks can't send their data to Anthropic. For a French institution that can't let its files cross the Atlantic, that isn't a features comparison. It's the only lawful option.

I won't sell you the flattering version, because the weaknesses are just as concrete.

Table 01
What Europe hasWhat Europe lacks
The one irreplaceable machine: ASML's lithography monopoly, which nobody, the US included, can reproduce. The chips themselves. They're designed in the US and fabricated in Asia; JUPITER, Europe's flagship supercomputer, runs on 24,000 American Nvidia chips.
A real frontier-adjacent lab in Mistral (~$20bn), able to run on a client's own hardware, under the client's own law. Scale. In 2025, American AI startups raised $165 billion; European ones raised $22 billion, a gap of nearly eight to one.
More AI talent per head than the US, and world-class universities training it. The salaries to keep it. American AI pay runs 30 to 70% higher, and Europe's best engineers leave.
The world's first comprehensive AI law, and the instinct to write rules others copy. The data centers, and lately the nerve to enforce the law it wrote (more on that below).

Europe's attempts to build its own model have a mixed record worth being frank about. "Lucie," a French government-backed chatbot, launched in early 2025 and was pulled after two days when it announced that five times five is seventeen. Aleph Alpha, Germany's great model hope, admitted it couldn't keep up and was absorbed by a Canadian company. Gaia-X, the grand European cloud project, let the American giants in and produced, in one founder's words, a "paper monster."

The pattern under all of it is speed. Europe announced €200 billion for AI in February 2025 and called it "a CERN for AI." The law needed to actually build the first facility only took effect in January 2026, the tender has slipped to this summer, and construction starts in 2027. Announcements arrive in months; concrete arrives in years. The one place Europe is moving with the grain of the technology is a quiet strategic shift: instead of trying to out-build a frontier model, run open models, the ones whose internals anyone can download, on your own European hardware, under your own law. The volume of computing done on open models has exploded, and for most real work they're now good enough at a fraction of the cost. But even this carries a twist you should see clearly, because it complicates the patriotic version of the story: the best open models being downloaded today are increasingly Chinese. Europe's most promising path away from American infrastructure currently runs, in part, on Chinese models and entirely on Dutch machines. Sovereignty is never total. It's a question of who you'd rather depend on, and how much.

The Argument

Build, don't just regulate

Which brings me to the thing Europe is best known for in all of this, and my one real argument.

Europe wrote the world's first comprehensive AI law, the AI Act, and it's a genuinely elegant piece of drafting, the kind you'd admire. It's a pyramid of risk: a handful of uses banned outright (social scoring, mass face-scraping, emotion detection at work), a set of "high-risk" uses tightly controlled, and everything low-risk left alone. The high-risk list reads like a tour of your world: hiring, credit scoring, exam grading, and, in the text's own words, "researching and interpreting facts and applying the law to concrete facts." It borrows its whole structure from a law you already know intimately, the GDPR: reach beyond Europe's borders, fines scaled to global revenue, obligations proportioned to harm. On paper it's the most serious attempt anyone has made to govern this technology.

And then, three weeks ago, Europe blinked. On 29 June, before the strictest parts of the AI Act had ever taken effect, the EU adopted an "omnibus" that postponed the high-risk rules, the ones covering hiring and credit and justice, from this August to late 2027 and 2028. The official reason is that member states and standards bodies weren't ready; only a handful had even named the authorities meant to enforce the law. The unofficial reasons are a competitiveness panic, open American hostility, and record industry lobbying. Civil-rights groups call it the largest rollback of digital protections in EU history, softened with a popular new ban on AI "nudifier" apps. Here is the detail that captures the whole situation: as I write this, the European Commission has never once had the power to fine a company that makes one of these models. That power was set to arrive on 2 August. It may now arrive later, and for less.

Fig. 4
BANNED HIGH-RISK LOW-RISK BANNED OUTRIGHT social scoring · mass face-scraping emotion detection at work IN FORCE SINCE 2 FEBRUARY 2025 HIGH-RISK, TIGHTLY CONTROLLED hiring · credit scoring · exam grading "applying the law to concrete facts" WAS DUE 2 AUGUST 2026 NOW LATE 2027 AND 2028 EVERYTHING LOW-RISK left alone NOTHING TO ENFORCE BANNED HIGH-RISK LOW-RISK BANNED OUTRIGHT social scoring · mass face-scraping emotion detection at work IN FORCE SINCE 2 FEBRUARY 2025 HIGH-RISK, TIGHTLY CONTROLLED hiring · credit scoring · exam grading "applying the law to concrete facts" WAS DUE 2 AUGUST 2026 NOW LATE 2027 AND 2028 EVERYTHING LOW-RISK left alone NOTHING TO ENFORCE
Fig. 4: The pyramid of risk, to scale. The tier that is already law is the small one at the top, the tier that was never regulated is most of the pyramid, and the one tier with real obligations for hiring, credit, and justice, hatched here, is the part pushed to late 2027 and 2028.

I'm not against the AI Act. Rules that stop people from being scored, surveilled, and refused a loan by an unaccountable machine are worth having, and Europe's instinct to write them first is one of the better things about it. My argument is narrower, and I think harder to dodge. The scholar who coined the very phrase for Europe's regulatory influence, Anu Bradford, is also the one who stated the real problem most clearly: over-regulation is not why Europe has no Google. The reasons are a fragmented market, shallow capital, a punitive bankruptcy law, and a talent policy that ships its best engineers abroad. Her own line is the one I'd leave with you: abandoning digital regulation "is not what will get it there." Weakening the rules doesn't build a single data center, train a single engineer, or make a single chip. Europe is busy negotiating down the one thing it does well, credible law, while doing far too little about the things it lacks.

So here's where I land, and it's the reason I bothered to write all this down for you. The Fable shutoff, the CLOUD Act, the Microsoft director's "je ne peux pas le garantir," the prosecutor locked out of his inbox: none of those are problems a law can fix, because they're all downstream of not owning the machines. A rule tells an American company how to behave in Europe. It doesn't give Europe an alternative when that company is compelled by its own government to behave differently. The only thing that does is building: European chips (the one part Europe already leads), European data centers, European models good enough that a French bank or a French court or a French lawyer has a real choice, one that keeps their files on this side of the Atlantic and under this side's law. Europe already knows how to write the rules for a technology. What it has to learn, fast, is how to build the thing the rules are about. Regulate the machine, by all means. But first, own one.