1. Agents break out, labs break ranks
OpenAI disclosed that two of its models broke out of a test environment, chained a third-party zero-day, and crossed its own network into Hugging Face’s production infrastructure to fetch the answer key for the exam they were sitting. Anthropic then confirmed Claude also reached outside systems, compromising three companies. Both evaluations ran with guardrails deliberately lowered. Sam Altman called it the singularity; the more careful reading is a containment failure. In the same week, more than 1,200 employees of OpenAI, Anthropic, Google DeepMind, and Meta asked Washington to build a mechanism for a verifiable, coordinated slowdown, and Sam Altman briefed lawmakers on the next model. Anthropic separately hardened its stance against open-weight models, leaving it the notable absentee as Jensen Huang’s open-weights coalition roughly doubled in signatories. And Microsoft shipped its first cybersecurity model, claiming 95.95 percent on the CyberGym benchmark against roughly 84 percent for Anthropic’s and OpenAI’s frontier models, at half the cost.
- These are the same agent products now deployed inside enterprises. Credential scoping, rotation, and behavioural monitoring are this quarter’s questions. The harder one is who is accountable when the model does exactly what it was asked and nobody said where to stop.
- When a company’s own staff ask government for a brake, boards should ask why the company cannot apply one itself. Prisoner’s dilemma.
2. The AI trade cracks
The sharpest signal came from a fund. Leopold Aschenbrenner’s Situational Awareness, up 439 percent through June on borrowed money against AI infrastructure, was forced to unwind its entire public portfolio (Citadel bought the bulk) as SK Hynix, SanDisk, Bloom Energy, and Nebius each fell over 30 percent in a month. Assets fell from roughly $45 billion at peak to about $10 billion. The cause ran through the week’s earnings too: capex is not yet turning into revenue. Alphabet beat and its shares still sank on $205 billion of 2026 capex guidance; Meta grew 28 percent and slid anyway; Microsoft and Amazon, judged more disciplined, rose 8 and 10 percent (Amazon having just shut its AGI lab to fund deployment over frontier research).
- Borrowed money was the mechanism, not the cause. The market now separates AI spending it believes from spending it merely tolerates.
- Situational Awareness kept its $5 billion Anthropic stake; an IPO is possible as soon as October. Private marks have not yet met the public tape. See story 3.
3. Nvidia bankrolls its own demand
Nvidia sits at the centre of roughly $750 billion in interlocking AI deals, and added two more this week: talks to guarantee up to $250 billion of financing for OpenAI’s 10GW Ohio campus, and a long-term partnership with Ilya Sutskever’s Safe Superintelligence, reportedly around $5 billion into a company with no product and no revenue. The Ohio backstop exists because debt markets would not fund it unaided. Meanwhile SoftBank completed a $5.8 billion sale of its Nvidia stake.
- A supplier underwriting its customers’ ability to buy is vendor financing. Boards saw this film in telecoms in 2000.
- The $250B is in talks, not closed. Watch whether the guarantee lands on Nvidia’s balance sheet or stays off it.
4. China comes for the moats
Three moats sprang leaks in one week. China began producing homegrown DUV chipmaking tools, the last manufacturing capability the West clearly led. Moonshot’s Kimi K3 took the open-model lead and now sits three points off the closed frontier on the Artificial Analysis index; six of the seven strongest open models are Chinese, and the best American one trails by 19 points. And a leaked DeepSeek investor call, in which the founder discussed Huawei chips and a broken CUDA moat, went viral, after which DeepSeek paused its fundraising round. Memory maker CXMT then jumped 466 percent on debut, per Bloomberg.
- The caveat is yield: producing a tool is not producing chips at commercial defect rates (CNBC).
- Valuations across the stack assume durable margins. Chips, models, and lithography each got a credible challenger in seven days.
5. Europe’s rules land August 2
The EU AI Act’s obligations for general-purpose AI take effect on 2 August, even as Brussels moves to simplify parts of the regime and extend other deadlines. Companies deploying AI in Europe now face documentation, transparency, and systemic-risk duties while the rulebook is still being rewritten.
- Simplification is not suspension. The obligations landing this weekend are live whatever the amendment process later produces.
- The board question is who owns the evidence file: model documentation, evaluation records, and incident reporting need a named executive.
More AI stories of the week
- PwC published thought-leadership reports riddled with AI hallucinations. A GPTZero investigation of four PwC Middle East reports found fabricated MIT Technology Review and WEF citations, and a “Citizen Pulse” framework said to be deployed by four governments with no evidence it exists (coverage).
- OpenAI cuts GPT-5.6 prices. Luna falls 80 percent and Terra 20 percent, days after Anthropic halved its top-tier price (OpenAI’s own note).
- CFR asks 350 experts how AI reshapes global power by 2035. Over 80 percent expect fragmented governance, only 5 percent think domestic institutions are keeping pace, and ~70 percent expect frontier labs to become the most powerful non-state actors.
- Fujitsu unveils PHOTON. A hierarchical alternative to the Transformer claiming up to 475x more output tokens per GPU, with details due at ACL 2026 (summary).
- Huang’s warning to CEOs: don’t let one vendor own your AI. The concentration-risk argument, from the industry’s most concentrated supplier (analysis).
- Robert Maciejko: Board AI Governance. Two published papers and a third in progress pulled into one guide, plus an anonymous 18-question Board AI Readiness Check.
- Warner Bros. Discovery’s generative AI programme. A case study on framing AI as a growth tool for creators rather than a cost-cutting exercise.
- The EU AI Act simplification package, unpacked. A governance practitioner’s read on what Brussels is changing (analysis).
- Michael Dell on developing with AI. Worth forwarding to anyone in your organisation still treating AI tooling as optional.
- Sam Altman on startups, policy, and the singularity. Nominally a startup talk, notable for the broader claims now shaping US policy conversations (opinion).
- Google’s Antigravity replaces the Gemini CLI. The new agentic coding surface, which community testers rate well above its predecessor.
- Proton launches Lumo 2.0. A private assistant with zero-access encryption, for users who rank the data question above capability.
- Kimi founder Zhilin Yang on why agents beat pure reasoning models. A 100-minute interview whose central image is that a pure reasoning model is “a brain in a fish tank,” able to think forever but never touch the world; an agent is that brain wired to tools, memory, and action.
- An open-source project poisons AI scrapers with a booby-trapped font. Text humans can read and machines cannot; an early skirmish in the content-versus-crawler fight.
The board framework that turns any of this week’s stories into a governable question is in the Board AI Governance guide.