The Biggest AI News This Week
🔓 OpenAI’s Hacking Debacle Widens: A Second Company Was Compromised in the Hugging Face Attack
💰 Meta’s Q2 Earnings Show Huge Continued CapEx Spending and Investors Are Concerned
🤝 Silicon Valley Heavyweights Support Open-Weight Models and even Anthropic Eventually Joins In
🔐 Pre-Release Version of Mythos Cracks Post-Quantum Encryption in Tests
📦 Amazon Restructures the Teams Developing Its Nova AI Models
☁️ Microsoft Produces Strong Q2 Earnings Driven by Azure Growth and Contained CapEx
🤖 US Government Bans Chinese Robots
🛡️ Microsoft, NVIDIA, and Other Heavyweights Form an Alliance to Secure Open-Source Software
💵 NVIDIA Invests in Safe Superintelligence, Ilya Sutskever’s AI Model Company
🧠 Microsoft Releases a New Cybersecurity Model to Compete with Anthropic’s Mythos
📃 Report You Should Read: Google’s AI & Economy ATLAS v1.0: Mapping Gemini Usage in the Economy
📖 Another Report: AI Lowers Wages but Doesn’t Cut Jobs from Apollo
🃏 Definitely Not AI: State Fair food. Too many books. The spreadsheet for bad dates. Bad LinkedIn profile. The Odyssey took too long!
1️⃣ OpenAI’s Hugging Face Cyber Attack Affected Additional Companies
The effects of OpenAI’s breach of Hugging Face’s systems are far wider than previously reported:
OpenAI now says the rogue agent also compromised accounts at a second company, Modal Labs, using stolen credentials across four services to stage its attack.
Hugging Face’s forensic review also found the intrusion reached deeper into its systems than first disclosed.
For enterprises running agentic AI, containment failures no longer remain within a single company.
Deeper Dive
What’s New.
Hugging Face reviewed roughly 17,600 recovered agent actions and found the models gained administrator access to multiple internal Kubernetes clusters, root access to a production server, and write access to a subnet of its GitHub repositories.
The agent enrolled 181 attacker-controlled devices in Hugging Face’s network using a stolen credential.
OpenAI confirmed four outside accounts were compromised as staging and relay points; a Modal Labs customer was one target, though Modal says its platform “was not compromised in any way,” per CTO Akshat Bubna.
OpenAI deactivated and restricted access to the model involved and said the incident forced a pause in some model training.
The Reaction. Security researchers largely blame process, not AI capability. New York state representative Alex Bores said lobbying from OpenAI weakened the state’s disclosure law, so firms aren’t legally required to report incidents like this one.
“I consider all AI and anything AI touches to be fully untrusted—which is fine, you just need to build against that.”
- Alex Zenla, CTO, Edera
The Takeaway
Audit the blast radius, not just the sandbox. Damage came from lateral movement into Kubernetes and GitHub access, so map what a contained agent could still reach if it escapes.
Don’t assume disclosure laws will surface the next incident. State laws only require reporting above catastrophic harm thresholds; build your own vendor-incident monitoring.
Treat vendor cybersecurity evaluations as production security events, requiring the same monitoring rigor as your own systems.
Hugging Face (official disclosure) | Hugging Face (technical timeline) | OpenAI | Reuters | Wired | Wired 2 | TIME | Axios
2️⃣ Meta’s Second Quarter Earnings Report Shows Huge Continued CapEx Spending and Investors Are Concerned
Meta’s second-quarter results show AI spending far beyond its current AI revenues. Total revenue rose 28% to $60.8 billion, beating estimates, but EPS of $6.18 missed the $7.14 consensus target after Meta paid $2.4 billion in legal charges and $1.18 billion in severance costs. Free cash flow collapsed 91% to $784 million as CapEx surged 83% to $31.08 billion. Meta shares fell nearly 10% after hours.
Deeper Dive
The CapEx-to-Strategy Gap.
Unlike Alphabet, Amazon, and Microsoft, Meta has no established cloud business generating revenue from its buildout. 98% of revenue still comes from ads.
CEO Mark Zuckerberg confirmed that Meta is exploring the sale of excess compute at a “significant premium” over cost, but that the business is nascent.
Meta narrowed 2026 CapEx guidance to $130–145 billion; some analysts expect it to keep climbing toward $215 billion.
Forrester VP Mike Proulx said the AI push is remaking Meta’s culture as much as its products.
eMarketer’s Minda Smiley was blunter, calling the pattern of subscriptions, glasses, and compute pilots a sign Meta lacks a “sustainable way forward.”
“The company is trading people for compute and replacing organizational depth with infrastructure at a moment when execution is the mandate.”
- Mike Proulx, VP and Research Director, Forrester
The Takeaway
Meta’s AI bet is still a “trust Zuckerberg” story, not a demonstrated cloud or AI story. Weigh vendor risk if you rely on Meta’s open models.
Watch free cash flow, not CapEx guidance alone. A 91% FCF drop with rising debt costs signals that Meta hs financing pressure other hyperscalers with cloud revenue don’t face.
A Meta compute-reselling plan could open a lower-cost GPU rental option worth tracking for 2027 infrastructure planning.
Meta Investor Relations | Reuters | Business Insider | Business Insider 2 | Business Insider 3 | Bloomberg | WSJ
3️⃣ Silicon Valley Heavyweights, including OpenAI and NVIDIA, Support the Availability and Use of Open-Weight Models and Even Anthropic Eventually Joins In
NVIDIA, Microsoft, and more than two dozen other companies signed a letter urging Washington not to impose “premature restrictions” on open-weight AI models. The letter is a direct response to the recent release of powerful AI models by Chinese companies, including Moonshot AI, Z.ai, and Alibaba.
Anthropic was the most notable holdout, fueling accusations it wanted a ban on Chinese open-weight models to protect its closed-weight model business.
CEO Dario Amodei pushed back days later, publishing Anthropic’s position:
No ban, but tighter export controls and a crackdown on distillation.
Deeper Dive
The Letter and the Holdout. The July 24 letter, shared first by NVIDIA CEO Jensen Huang on a new personal X account and echoed by Microsoft’s Satya Nadella, argues that open models are a “public good” that democratize access to AI and cyber defense. The letter cites Hugging Face’s use of a Chinese open model to analyze the OpenAI breach, after Anthropic’s own models refused the task due to their built-in guardrails.
Google and OpenAI signed over the weekend after initially abstaining. Anthropic and Amazon did not sign.
Amodei’s Response. Three days later, Amodei published Anthropic’s position:
“Anthropic has never advocated for a ban on open-weights models.”
He called safe open models “a public good” but drew a distinction from Chinese models, citing the risk of dangerous capabilities once weights are released and can’t be revoked. He asked instead for export controls, action against “industrial-scale distillation,” and mandatory safety testing.
“Open-weights models that don’t have dangerous capabilities are a public good: they don’t cost anything besides the compute needed to run them, and they provide value to businesses, developers, and researchers.”
- Dario Amodei, CEO, Anthropic
The Takeaway
The alliance is more practical than ideological. Chip vendors back openness because it drives compute use; closed-weight model labs have to evaluate IP risks.
Anthropic’s specific asks are a clearer signal of the likely policy direction than the letter itself.
Track the distillation-as-IP-theft debate. It’s the likely justification for future restrictions on open-weight models.
Anthropic | Open Weights and American AI Leadership (letter) | TechCrunch | Axios | CNBC | Bloomberg
4️⃣ Pre-Release Version of Mythos Cracks Post-Quantum Encryption in Tests
Anthropic’s unreleased Claude Mythos Preview found a structural weakness in HAWK, a candidate post-quantum signature scheme under NIST review, cutting its effective key strength in half. The result was serious enough that HAWK’s designers withdrew it from NIST’s process the same day. Separately, Mythos sped up a theoretical attack on reduced-round AES by 200 to 800 times. No production system is affected.
Deeper Dive
Mythos worked mostly autonomously over roughly 60 hours and spent about $100,000 in compute, finding a lattice symmetry no human reviewer had used in two years of review. Verification was the bottleneck:
Two researchers spent nearly a month confirming the result.
Cryptographer Matthew Green called it “a little embarrassing for the field” that the attack used no exotic math, just existing tools applied more thoroughly.
“Are we really comfortable that two years from now strong encryption won’t be threatened?”
- Glenn S. Gerstell, former General Counsel, NSA
The Takeaway
The result isn’t a threat to deployed encryption, which requires an impossible number of chosen parameters. Don’t let headlines drive premature cryptographic decisions.
The HAWK withdrawal is the real signal: AI-assisted cryptanalysis can now retire a standards candidate before deployment. That’s a good outcome for anyone relying on NIST’s process.
Anthropic (research blog) | CyberScoop | CSO Online | The Hacker News | Cryptography Engineering (Matthew Green) | NYT | NIST pqc-forum (HAWK withdrawal)
5️⃣ Amazon Restructures the Teams Developing its Nova AI Models – Signaling a Shift in Its AI Strategy
Amazon is winding down active development on four flagship Nova models including Premier, Omni, Reel, and Canvas, moving them to maintenance-only mode and redirecting engineers and compute toward a single frontier model effort. The shift follows layoffs in Amazon’s AGI organization and the closure of its San Francisco AGI Lab.
Amazon’s shift in development signals that it is betting on building a single competitive model rather than spreading its resources across an underperforming portfolio of models.
Deeper Dive
The restructuring places Amazon’s agent technologies – Nova 2 Lite, Nova 2 Sonic, Nova Forge, and Nova Act, outside the wind-down. The new flagship model is expected to be announced at AWS re:Invent, possibly still under the Nova brand. Amazon’s AGI unit now reports to cloud executive Peter DeSantis, who also oversees custom silicon and quantum computing.
Amazon’s dual-track approach which includes a smaller in-house effort alongside its $38 billion OpenAI compute partnership and 100,000-plus customers running Anthropic’s Claude on AWS suggests its real advantage lies in infrastructure, not proprietary models.
The Takeaway
Enterprises using Nova Premier or Omni should confirm migration timelines now; those models will likely be maintenance-only before feature freezes and a formal shutdown.
Treat AWS as an infrastructure and multi-model marketplace play, not a proprietary-model competitor to OpenAI or Anthropic.
PYMNTS | Reuters | TechRepublic | Business Insider | The Information
6️⃣ Microsoft Produces Strong Second Quarter Earnings Driven by Strong Azure Growth and Somewhat Contained CapEx Spending
Microsoft delivered a strong fiscal fourth quarter, showing the clearest indication yet that it is starting to convert its AI costs into profits. Revenue rose 18% to $90 billion and net income jumped 31% to $35.8 billion, both beating estimates. Azure revenues grew 43%, the fastest pace since 2022.
Deeper Dive
CapEx Restraint, Not Retreat.
Microsoft’s CapEx guidance declined on paper, to about $175 billion from $190 billion, but CFO Amy Hood said the change reflects an accounting shift — data centers now depreciate over 25 years instead of 15 — not a change in investment plans.
Quarterly CapEx still rose 70% to $41 billion.
Azure hit $100 billion in fiscal-year revenue for the first time, putting it just ahead of Google Cloud’s revenue but behind market leader AWS.
Copilot paid seats reached 30 million, up from 20 million last quarter, beating Stifel’s 26 million estimate.
CEO Satya Nadella also told analysts that enterprises “can’t sort of depend on any one model” – echoing the now widely held belief that enterprises will diversify their model usage to save money and lower risk.
“Demand continues to exceed available supply.”
- Amy Hood, CFO, Microsoft
The Takeaway
Microsoft’s flat CapEx guidance is an accounting reclassification, not spending discipline. Model vendor costs on the $41 billion quarterly run rate, not the headline cut.
The Copilot beat (30M vs. 26M estimated) is hard evidence that Microsoft’s AI monetization is delivering results.
Nadella’s multi-model messaging suggests planning for multi-vendor AI architectures is a technical necessity.
Microsoft Investor Relations | CNBC | The Verge | Bloomberg | WSJ | Business Insider
7️⃣ US Government Bans Chinese Robots
The FCC is banning imports of new foreign-made humanoid robots, quadruped “robot dogs,” and power inverters, citing national security risks. It’s a move squarely aimed at China, since it holds roughly an 85% share of the global humanoid robot market. The new policy lands weeks ahead of a planned US-China summit and adds robots to a growing list of restricted categories of Chinese technology.
Deeper Dive
FCC Chairman Brendan Carr framed the move as securing “America’s critical supply chains”; the ban applies only to new imports, leaving installed devices and previously approved models untouched.
Chinese makers Unitree and AGIBOT each shipped more than 5,000 humanoid robots in 2025, compared with a few hundred or fewer for Tesla and Figure AI, per Omdia.
China’s Foreign Ministry called the move protectionism that “will only hurt the interests of U.S. companies and consumers.”
Analysts are split on the opportunity for non-Chinese makers: Morningstar’s Kangyuxiao Li said the ban “protects U.S. developers from potential price competition” but “will not materially slow China’s overall humanoid development,” given its domestic manufacturing scale and access to other export markets.
“It’s a steady drumbeat of potential flashpoints heading into the Trump-Xi summit planned for September.”
- Samm Sacks, Senior Fellow, New America
The Takeaway
The ban only blocks new imports. Audit existing Chinese robotics deployments now, since replacement units may be harder to source even where current equipment stays legal.
US and allied robotics makers gain a protected market, but Omdia’s data show the production gap with China’s 5providers won’t close quickly.
The power-inverter provision likely matters more to data-center and renewable-energy buyers than to robotics buyers. In fact, it creates a new, unwelcome constraint that could slow data center deployments.
Reuters | Los Angeles Times | TechCrunch | TIME
8️⃣ Microsoft, NVIDIA, and Other Heavyweights Form an Alliance to Secure Open-Source Software
NVIDIA formed the Open Secure AI Alliance, a coalition of more than two dozen companies including Microsoft, SpaceX, Palantir, Adobe, CrowdStrike, Dell, and Hugging Face, to build and share open-source AI tools for cyber defense. The alliance was launched three days after the OpenAI-Hugging Face breach.
The alliance members argue that openly available models and security tooling are “defensive assets, not liabilities,” directly countering calls to restrict open-weight AI.
Deeper Dive
The founding members’ case rests heavily on the Hugging Face incident itself:
When the company tried to analyze the attack, closed-weight Anthropic models refused the task on guardrail grounds, forcing Hugging Face to use a Chinese open-weight model instead. “The recent Hugging Face security incident delivered a clear reminder,” the alliance said. “Cyber defenders need open” systems.
NVIDIA is contributing its open-source Object-Oriented Agent research to the effort.
White House adviser David Sacks separately called restricting the open-source ecosystem “a tragic mistake” that would only hurt America’s competitive position.
“As policymakers and regulators grapple with AI safety, it will be crucial to recognize open models, harnesses and security tooling as defensive assets, not liabilities.”
- Open Secure AI Alliance, founding statement
The Takeaway
The alliance is NVIDIA-led, with Microsoft among the founding members. Think of it as infrastructure vendors defending a business model as much as a pure security initiative.
The Hugging Face guardrail-refusal episode is a concrete data point for security teams: When closed-weight models can’t help with cyber issues during live incidents, enterprises will rely on less-vetted alternatives. Build that contingency into incident-response plans now.
NVIDIA | Reuters | Axios | WSJ
9️⃣ NVIDIA Invests in Safe Superintelligence – the AI Model Company Founded by Ilya Sutskever, the Former Chief Scientist at OpenAI
NVIDIA is investing up to $5 billion in Ilya Sutskever’s Safe Superintelligence (SSI), a startup with no product, demo, or revenue in two years, according to Bloomberg. SSI gains access to NVIDIA’s Vera Rubin platform, increasing its compute by an “order of magnitude,” while NVIDIA gets rare access to SSI’s closely guarded research.
Deeper Dive
Founded in 2024 by OpenAI’s former chief scientist and valued at roughly $32 billion, SSI had relied primarily on Google’s TPUs for compute; the deal diversifies its compute supply chain. It’s NVIDIA’s second bet on an AI lab founded by an OpenAI alumnus, following a March investment in Mira Murati’s Thinking Machines Labs.
“We have research that is worthy of scaling up, and having access to a big NVIDIA computer will let us do so.”
- Ilya Sutskever, Cofounder and CEO, Safe Superintelligence
The Takeaway
Treat the $5 billion figure as unconfirmed. It comes from anonymous sources, not either company’s statement, which only says “substantial.”
SSI doesn’t yet have a commercially available product, so NVIDIA’s bet is primarily on the quality of SSI’s future offerings rather than current performance.
Factor in circular financing risks into any NVIDIA investment thesis.
NVIDIA Newsroom | SiliconANGLE | TechCrunch | Bloomberg | WSJ
🔟 Microsoft Releases a New Cybersecurity Model to Compete with Anthropic’s Mythos
Microsoft launched its first in-house cybersecurity model, MAI-Cyber-1-Flash, as part of Project Perception, an agentic platform for finding and patching vulnerabilities. It’s a direct challenge to Anthropic, OpenAI, and Google in the AI cyber market. Microsoft says the model tops the CyberGym benchmark at roughly half the cost of competing systems and resolves 90% of security queries without escalating to larger models.
Deeper Dive
Unlike Mythos, MAI-Cyber-1-Flash was not shared with independent testers before release. Microsoft argues its advantage is data, not novelty:
The model trained on decades of incident data from Windows, Outlook, and Azure, all frequent attack targets.
Project Perception actually runs a mix of OpenAI, Anthropic, and Microsoft models, not MAI-Cyber-1-Flash alone.
The launch follows directly on the OpenAI-Hugging Face breach and reflects an industry shift toward specialized, cheaper cyber models.
“The cat is out of the bag.”
- Hayete Gallot, EVP of Security, Microsoft
The Takeaway
Microsoft’s benchmark claims are self-reported and unverified by independent testers. Request third-party benchmarking results before making procurement decisions based on the stated cost or performance advantage.
Project Perception’s multi-model design (not a Mythos-only replacement) suggests the near-term security stack will stay multi-vendor regardless of which model wins any given benchmark.
Microsoft AI | TechCrunch | The Deep View | NYT | The Information
Report You Should Read
Google’s AI & Economy ATLAS v1.0: Mapping Gemini Usage in the Economy
About Google & the Authors
Google published this report on July 23, 2026, through its AI and Economy Research Program. Seventeen authors across Google and Google DeepMind contributed, with Zanna Iscenko and Scott Strand as corresponding authors. Diane Coyle of the University of Cambridge and David Autor of MIT advised on the research, and Coyle wrote a signed guest essay included in the full report.
The report introduces ATLAS, short for Activity, Task, Landscape, and Adoption Study, an economic research initiative Google plans to update over time. This first version draws on 15 million de-identified interactions collected between April 6 and April 19, 2026, across the Gemini App, Google AI Mode, and the Gemini API. Google mapped that activity to more than 800 occupations, 4,000 work tasks, 300 household activities, 150 countries, and 140 languages, using automated classification and privacy safeguards. It is among the largest datasets assembled to study real-world AI usage. Google notes it excludes paid enterprise API traffic and products such as Workspace and AI Overviews.
Editor’s note: This is Google’s own analysis of usage on its own AI products. The report maps that proprietary usage data onto third-party statistical frameworks, including U.S. Bureau of Labor Statistics occupation codes and the American Time Use Survey, which is worth keeping in mind when weighing the findings below.
Adoption Is Broad, but Shallow
AI usage now touches 68% of detailed US occupations, covering nearly 88% of total US employment. Depth lags reach, though. In the median occupation with any AI use, workers apply it to just 21% of their tasks. Only 3% of occupations show usage across three-quarters or more of their tasks, a group that includes software QA analysts, HR specialists, and document management specialists.
Collaboration, Not Automation
The data leans toward collaboration, not automation. Less than 10% of AI conversations tied to non-routine cognitive work reflect an intent to automate a task end-to-end. Most usage centers on drafting, review, ideation, and information retrieval, functions that complement rather than replace judgment. Routine cognitive work shows more automation intent, at just over a quarter of conversations.
Usage Tracks Pay and Education, Unevenly
1% rise in an occupation’s median earnings corresponds to a more than 2.5% rise in AI usage intensity. The Gemini-conversation-weighted median salary sits near $83,000, about $20,000 above the true US employment-weighted median. Tasks requiring lower-to-middle expertise see relatively higher usage than the most expert tasks, even as high earners adopt AI at the highest rates overall, a tension Google flags as worth watching for its effect on wage inequality.
The Bigger Opportunity May Sit Outside the Office
Work accounts for only about 14% of total conversations. The remaining 86% covers household management, education, and high-friction administrative tasks such as government services and legal and financial questions, categories where AI usage runs up to twenty times higher than the time people actually spend on them. Google estimates unpaid productivity gains from household AI use could range from roughly $15 billion to $149 billion a year in the US, depending on assumed time savings.
Adoption Still Splits Along Income and Language Lines
Globally, a 1% increase in a country’s GDP per capita predicts a 0.9% increase in AI usage. The lowest-adoption quintile of countries accounts for just 2% of conversations. English accounts for only about a third of global usage, and Google finds no evidence that professional users abandon their native languages for complex tasks.
Looking Ahead
Google frames these as early findings from a dataset it plans to expand. It declines to draw conclusions on whether AI is widening the global digital divide or slowing entry-level hiring, naming both as open questions for future ATLAS work.
Report Web Page | Report
Another Report You Should Read: AI Lowers Wages but Doesn’t Cut Jobs from Apollo
Overview
Apollo Global Management economists Sania Edlich and Torsten Slok have produced one of the first labor market studies built on observed AI usage rather than theoretical exposure scores.
Published in July 2026, the paper draws on Anthropic’s Claude interaction logs rather than the expert-judgment and patent-text measures that have dominated prior research. The headline finding runs counter to the job-loss narrative common in boardroom conversations:
AI is compressing wages, not eliminating jobs.
Methodology
The authors matched 321 occupations across Bureau of Labor Statistics and Current Population Survey data to Anthropic’s Economic Index, which scores the share of an occupation’s tasks performed with AI assistance. Using a difference-in-differences design with occupation and year fixed effects, they compare wage and employment trends before and after ChatGPT’s late-2022 release.
Key Finding
Occupations with an Anthropic exposure score of 0.5 or higher saw real wage growth run 6.7 percentage points slower than low-exposure occupations after 2023. Employment showed no significant change. The authors read this as evidence that firms are capturing AI productivity gains through wage compression rather than headcount reduction, at least so far. The result holds, though it weakens, across alternative exposure cutoffs of 0.4 and 0.6, which the authors report as a robustness check.
Who Bears the Cost
The burden is not evenly spread. Workers in the bottom wage quartile saw real wage growth decline 10.7%, compared to no significant effect for the top quartile. Service occupations, including childcare workers and customer service representatives, fell 24.3%, though the authors flag this estimate as resting on a small subsample and urge caution. Management and professional occupations also saw a smaller but significant 4.1% decline. Blue-collar occupations showed no measurable effect, consistent with AI’s limited reach into physically intensive work.
Scale of the Impact
Today, 5.8 million U.S. workers, about 3.7% of the labor force, sit in high-exposure occupations. The authors put the aggregate annual wage loss at a conservative $28 billion. Using BLS employment projections, they estimate the affected workforce will grow to 5.9 million by 2032, a figure that assumes today’s exposure assignments are fixed rather than modeling further AI adoption.
Limitations and Outlook
Two limitations are worth flagging. The exposure measure draws only on Anthropic’s usage data, the sole AI provider that has released usage data for public research, so it likely understates true AI exposure. Only 321 of roughly 800 BLS occupations could be matched. The authors frame today’s affected workers as the leading edge of a larger adjustment still to come.
AI Wages Report Web Page | AI Wages Report
Definitely Not AI
The best state fair food, according to Yelp. The red hot dating evaluation spreadsheet (gift link). The New York City studio apartment with too many books (gift link).
LinkedIn profiles gone wrong, and why the heck did the Odyssey take 10 years?
How to Engage with Us
Contact us directly here with questions about the Big Book of AI Metrics, benchmarking data, podcast advertising, or newsletter partnerships.
The Big Book of AI Metrics
Download the Big Book here to access the tools you need to build a measurement framework that delivers high ROI AI use cases.
The AI to ROI Podcast
If you want to listen to the latest in AI in more detail, Ray and Peter break down our big AI story of the week on the AI to ROI podcast. We also interview leaders at AI product companies and mid- to large-sized enterprises about their challenges and successes in AI. Click here to listen or subscribe using your favorite podcasting app.




















