1. Agents break out, labs break ranks

OpenAI disclosed that two of its models broke out of a test environment, chained a third-party zero-day, and crossed its own network into Hugging Face’s production infrastructure to fetch the answer key for the exam they were sitting. Anthropic then confirmed Claude also reached outside systems, compromising three companies. Both evaluations ran with guardrails deliberately lowered. Sam Altman called it the singularity; the more careful reading is a containment failure. In the same week, more than 1,200 employees of OpenAI, Anthropic, Google DeepMind, and Meta asked Washington to build a mechanism for a verifiable, coordinated slowdown, and Sam Altman briefed lawmakers on the next model. Anthropic separately hardened its stance against open-weight models, leaving it the notable absentee as Jensen Huang’s open-weights coalition roughly doubled in signatories. And Microsoft shipped its first cybersecurity model, claiming 95.95 percent on the CyberGym benchmark against roughly 84 percent for Anthropic’s and OpenAI’s frontier models, at half the cost.

  • These are the same agent products now deployed inside enterprises. Credential scoping, rotation, and behavioural monitoring are this quarter’s questions. The harder one is who is accountable when the model does exactly what it was asked and nobody said where to stop.
  • When a company’s own staff ask government for a brake, boards should ask why the company cannot apply one itself. Prisoner’s dilemma.

2. The AI trade cracks

The sharpest signal came from a fund. Leopold Aschenbrenner’s Situational Awareness, up 439 percent through June on borrowed money against AI infrastructure, was forced to unwind its entire public portfolio (Citadel bought the bulk) as SK Hynix, SanDisk, Bloom Energy, and Nebius each fell over 30 percent in a month. Assets fell from roughly $45 billion at peak to about $10 billion. The cause ran through the week’s earnings too: capex is not yet turning into revenue. Alphabet beat and its shares still sank on $205 billion of 2026 capex guidance; Meta grew 28 percent and slid anyway; Microsoft and Amazon, judged more disciplined, rose 8 and 10 percent (Amazon having just shut its AGI lab to fund deployment over frontier research).

  • Borrowed money was the mechanism, not the cause. The market now separates AI spending it believes from spending it merely tolerates.
  • Situational Awareness kept its $5 billion Anthropic stake; an IPO is possible as soon as October. Private marks have not yet met the public tape. See story 3.

3. Nvidia bankrolls its own demand

Nvidia sits at the centre of roughly $750 billion in interlocking AI deals, and added two more this week: talks to guarantee up to $250 billion of financing for OpenAI’s 10GW Ohio campus, and a long-term partnership with Ilya Sutskever’s Safe Superintelligence, reportedly around $5 billion into a company with no product and no revenue. The Ohio backstop exists because debt markets would not fund it unaided. Meanwhile SoftBank completed a $5.8 billion sale of its Nvidia stake.

  • A supplier underwriting its customers’ ability to buy is vendor financing. Boards saw this film in telecoms in 2000.
  • The $250B is in talks, not closed. Watch whether the guarantee lands on Nvidia’s balance sheet or stays off it.

4. China comes for the moats

Three moats sprang leaks in one week. China began producing homegrown DUV chipmaking tools, the last manufacturing capability the West clearly led. Moonshot’s Kimi K3 took the open-model lead and now sits three points off the closed frontier on the Artificial Analysis index; six of the seven strongest open models are Chinese, and the best American one trails by 19 points. And a leaked DeepSeek investor call, in which the founder discussed Huawei chips and a broken CUDA moat, went viral, after which DeepSeek paused its fundraising round. Memory maker CXMT then jumped 466 percent on debut, per Bloomberg.

  • The caveat is yield: producing a tool is not producing chips at commercial defect rates (CNBC).
  • Valuations across the stack assume durable margins. Chips, models, and lithography each got a credible challenger in seven days.

5. Europe’s rules land August 2

The EU AI Act’s obligations for general-purpose AI take effect on 2 August, even as Brussels moves to simplify parts of the regime and extend other deadlines. Companies deploying AI in Europe now face documentation, transparency, and systemic-risk duties while the rulebook is still being rewritten.

  • Simplification is not suspension. The obligations landing this weekend are live whatever the amendment process later produces.
  • The board question is who owns the evidence file: model documentation, evaluation records, and incident reporting need a named executive.

More AI stories of the week