What changed on this site
Claude
This page covers tools outside your selection. You can still read it. Find matching guides
Corrections, retractions and findings worth knowing about if you read something here before. Silent on typos and tidying.
Every guide carries a verified_on date, which tells you when someone last checked it. This page tells you what changed when they did, which is the part a date cannot express.
Deliberately incomplete. Entries appear when something here was wrong, when a claim moved, or when a page turned up a finding worth knowing on its own. Typos, wording and new pages that simply extend coverage do not get an entry.
2026-09-04
Checked. UNESCO's guidance article went unreachable and the question was whether the page had moved. It has not: the URL still resolves in DNS, remains the canonical link in the live search index, and the entire host refuses TCP on ports 80 and 443 from two separate networks. That is an outage; a removal answers from a working server. The guidance document itself was then read via the UNESCO UK National Commission's PDF mirror, and the claims now on the students page — the age-13 threshold and the "new type of plagiarism" framing — are quoted from that primary text.
Finding. The OWASP LLM Top 10 is published against the 2025 list, because that is what OWASP's site carries as its live per-entry taxonomy. A 2026 edition exists only as a gated download, and second-hand summaries of it contradict each other — one blog's prose described 2026 reorderings while its own list showed the 2025 order. The page says which edition it covers; check which one your auditor means.
Restored (2026-09-06). The COPE citation is back, with the mystery solved: COPE relaunched its website, moving the position statement from /cope-position-statements/ai-author to /guidance/cope-position/authorship-and-ai-tools, and put the site behind bot protection strict enough that even the Internet Archive's crawler now receives 403s. The statement itself is unchanged (last reviewed 13 February 2023) and carries a DOI — 10.24318/cCVRZBms — which is the citation that survives such moves. Quotes were verified against an archived copy of the new page (Wayback, 2026-01-01) and are pinned in the local source archive; researchers, disclosure and writers and editors now cite COPE directly.
Corrected. Two pages stated COPE's position on AI authorship without citing COPE. publicationethics.org returns 403 to every automated client, so the statement could not be read, so the claim was removed. Sourcing it from somewhere that had summarised it would have been the same mistake. Disclosure and writers and editors now name only ICMJE, which is cited and verified. The attribution check covers COPE from now on.
Corrected. Three quoted claims did not match their sources. One had a word changed to fit the sentence around it, one quoted a summary of a page rather than the page, and seven carried a full stop the source did not have. All attributed quotes are now marked so they can be checked automatically against their sources on every weekly run.
Finding. Structured output: a large part of JSON Schema is unsupported, and the SDKs strip it silently in place of rejecting it. Write minimum: 0 and the model never sees it, so it can return -5 — valid JSON of the right type, so the API guarantee held, and your own validation is what catches it at runtime. Guaranteed-valid JSON and guaranteed-valid data are different claims.
Finding. Prompt caching: a prompt below the model's minimum cacheable length is processed without caching and no error is returned. cache_control is accepted, the request succeeds, and you pay full price indefinitely with nothing to indicate it. The minimum varies across four tiers and does not follow generation order, so a model migration can turn a working cache off silently.
Finding. Tool use: asked for the weather with no city, the model may return a call carrying an invented location and a unit parameter that was never part of the question. Anthropic documents this as model-dependent, with Opus more likely to ask and Sonnet more likely to infer. A guessed argument is indistinguishable from a supplied one by the time it reaches your handler.
Fixed. Four guides linked to a skills library that was a private repository, so every reader following them got a 404. The repository is now public and the links work. Found by extending the weekly link check to cover links written in prose, which it had never looked at.
Changed. Why Language Models Hallucinate is now cited as the paper on arXiv rather than as OpenAI's blog post about it. The blog post refuses automated clients, so nothing could verify it stayed alive; the paper is the primary source anyway.
Added. Anthropic's skills repository now appears alongside the opinionated one, in skills and in the documentation index. It carries the spec, a template and examples by category.
New. Secrets, credentials, and what never enters context. A Read deny rule covers Claude's file tools and the bash file commands it recognises. It does not cover a script that opens the file itself, which the documentation states plainly and which is the difference between a guardrail and containment.
Finding. Why context management is most of the skill. A Claude Code session loads roughly 7,850 tokens before you type, and a single source file read costs 1,100–2,400. A research subagent reads three files and returns 420.
2026-09-03
New. Official documentation, and when to go there instead. Where the vendor's pages beat ours, and the two cases where they authoritatively do: pricing, which our model matrix can lag by a day, and contractual terms.
2026-09-02
Corrected. Two security pages attributed a stronger position to the UK NCSC than its source carries. Both said the NCSC had called prompt injection something that "may never be fully fixed" — a prediction. What the NCSC actually writes is that at present there are no failsafe measures that remove the risk, which is a statement about now. Prompt injection and blast radius now quote the source and link it at the claim. Neither cited the NCSC at all before this.
Corrected. revDSG und KI cited a kmu.admin.ch page that had started returning 404, because admin.ch moved to short URLs. Replaced with the live page. While checking it, the 250-employee exemption from the processing register turned out to rest on an explainer rather than on the law, so Art. 24 DSV is now cited directly.
Fixed. Every date rendered on the site was malformed and a day early — Sun Aug 30 where 2026-08-31 was meant. YAML parses verified_on into a date object and the template was slicing ten characters off its text form. Affected the freshness date on all guides and every source access date.
Finding. Projects: past a threshold you cannot see, a project stops reading its knowledge base and starts searching it. Anthropic documents the switch. Nothing in the interface signals it, and a retrieval miss is indistinguishable from the model ignoring you.
Finding. Files and PDFs: a PDF of 100 pages or fewer has its charts and images analysed. From 101 pages it is text only. Nothing announces the crossing, so a question about a figure on page 140 returns an answer reconstructed from the surrounding prose.
Retired. Four planned pages were dropped as already covered elsewhere, rather than written as duplicates: what "the model doesn't remember" means, why you feel faster than you are, citations that do not support their claim, and plans and usage windows. The material is published; the plan pointed at the wrong files.
Before this
The site was built through late August 2026 and this log starts when the first correction did. Guides published before 2026-09-02 carry their own verified_on dates, and anything corrected since appears above.
What goes wrong
Reading an empty stretch as "nothing changed". This log records what we noticed. A claim that quietly went stale, on a page nobody re-checked, leaves no entry — which is what verified_on and the weekly staleness check are for.
Assuming a correction was the only instance. The NCSC entry above began as one page and turned out to be two. When something is wrong here, the useful assumption is that the same mistake may sit elsewhere.
Treating this as a release log. It is about claims, not features. New pages appear only when they carry a finding; the full list lives in the guide index.
How to check it worked
If you acted on something you read here before 2 September 2026, check whether its page appears above. If it does, re-read the corrected claim. If it does not, look at the page's verified_on date and judge whether the underlying vendor behaviour is likely to have moved since — for anything load-bearing, the official documentation is the place to settle it.
Sources
- Thinking about the security of AI systems — UK NCSC Tier 1 2026-09-02
- Datenschutzverordnung (DSV), SR 235.11 — Fedlex Tier 1 2026-09-02
Something wrong with this page?
Say what you expected and what you got. That is usually the shortest route to a correction, and it goes on the public issue tracker so the fix is visible.