The Big Picture: three labs admitted the same accident
For three issues we have followed one story: an OpenAI model, being tested for hacking skill, got out of its sealed test environment and broke into Hugging Face, the site where the industry keeps its models. It looked like one company’s bad week.

It was not. On July 30 Anthropic published a review of its own records and found three Claude models had reached three real companies during security drills, the earliest back in April. On August 6, Meta became the third. And in Anthropic’s case and Meta’s, the cause was the same and it is oddly mundane: an outside testing firm called Irregular, hired to run these drills, had left the practice machines connected to the live internet. The models were told they had no internet. They believed it. They went looking for the target they’d been asked to attack, found the real world instead, and treated it as part of the exercise.
One went further than the rest. During a drill, Claude Mythos 5 uploaded a booby-trapped software package to PyPI, a public library programmers download code from. Fifteen real machines downloaded and ran it. One belonged to a security company whose own scanner opened the file, which handed over passwords.
Then on August 7 OpenAI did something no AI company has done before. It published an assessment of Astra, the unreleased model behind last week’s mathematics results, saying its early tests show performance strong enough that it “cannot rule out the critical capability level at this time.” In OpenAI’s own rulebook, “critical” on cyber means a model that can find unknown holes in well-defended systems, or plan and run a full attack, with little or no human help. OpenAI locked Astra into isolated machines, encrypted the model itself, added monitoring, and paused internal work that didn’t meet the new controls. It has asked government agencies to test it before release.
Why this matters to you: the useful lesson here is not that AI is escaping. It is that the safety testing was sloppier than the technology. Two of these three cases were a contractor’s configuration error, the digital version of a lab leaving the freezer door open. That is fixable, and it is being fixed in public, which is better than the alternative. The genuinely new thing is OpenAI’s Astra note: a company saying, before shipping, that its own product might be too good at breaking into things. Whether that becomes a habit or stays a one-off is the question worth holding onto.
Sources: OpenAI · Anthropic · Help Net Security · TechCrunch · Yahoo Finance on Meta · The Hacker News
What’s New (and Why You’d Care)
The free version of ChatGPT just got the good model, and the meter came off. On August 6 OpenAI made GPT-5.6 Luna the default for free and low-cost Go accounts, and gave those accounts unlimited text conversations, with the unlimited part rolling out through this week. Free users also get a “Think” button that tells the model to spend longer on a hard question. Paying subscribers got a retuned version of the top model plus a slider that sets how hard it works on each answer. OpenAI says factual errors are 62% less common on the new free model and 68% less common on the paid one, measured against the versions they replace. Limits still apply to files, images and voice.

→ So what: if you last tried ChatGPT on a free account and found it capped, throttled, or dumber than the one your colleague pays for, that gap just narrowed a lot. This is also the clearest sign yet of what the price collapse we covered last week actually buys you: the labs are no longer rationing their good models, they’re using them to hold onto you.
The same update quietly added the first safety tests written for teenagers. Buried in the technical document OpenAI published alongside it: for the first time the company measured its models against teen-specific standards rather than adult ones, and published the scores. The model is now trained to refuse romantic roleplay with users it believes are under 18, to avoid presenting itself as a substitute for real relationships, and to steer toward a parent, teacher or counsellor when a teenager shows signs of distress. There are break reminders and parental controls.
→ So what: if you have a teenager, this is the thing in this issue that touches your house. Take the claim with appropriate salt, the company is grading its own homework, but publishing the scores is how outside researchers get something to argue with. Worth knowing this is voluntary: state legislators introduced more than 100 bills on AI companion chatbots this year and passed 14, so the industry is moving just ahead of the law.
Meta shipped its first coding agent, and undercut everyone on price again. On August 5 Meta released Muse Spark 1.2, a model built to work through software projects on its own, plus a companion tool called Muse Code. The number that matters is the price: a contributor tier starting at $0.10 per million words-worth of input, a fraction of what rivals charge for comparable work.
→ So what: you will not use this, and it still reaches you. Software is the first job AI is genuinely good at, and the cost of it just fell again from a company that gives its models away. The apps you use are built by people who now pay pennies for work that cost real money a year ago, which is why every product you own keeps sprouting AI features nobody asked for.
Sources: OpenAI’s system card · OpenAI’s announcement · TechCrunch · Axios · Meta AI Research · Yahoo Finance · TechPolicy.Press on state bills
Jobs & Work: layoffs hit a two-year low, AI stayed the top reason
Both of those come from the same report, published August 6 by Challenger, Gray & Christmas, the firm that has counted announced US job cuts for decades.
American employers announced 33,429 cuts in July. That is the lowest month in two years, down 27% from June and down 46% from July last year. Across 2026 so far, announced cuts are down 41% on the same stretch of 2025.

Inside that shrinking number, AI was named in 10,970 of July’s cuts, a third of the total, and the leading stated reason for the fifth consecutive month. Technology is the sector absorbing it: 149,023 cuts so far this year, up 67% on last year, and 31% of all US cuts from one industry.
The other half of the report gets less attention. Employers announced plans to hire 16,095 people in July, up 47% from June and the strongest July since 2022. “Hiring has also increased over last year by 25%, so while AI is shifting the labor market, it is not dismantling it,” said Andy Challenger, the firm’s chief revenue officer.
→ So what: the headline you’ll see is whichever half fits the writer’s argument. Both are true, and read together they say something specific: fewer people are losing jobs than last year, but a growing share of those who do are losing them to a stated AI decision, and it is heavily concentrated in tech. If you work outside technology, the risk in these numbers is smaller than the coverage suggests. If you work in it, the reverse.
Sources: Challenger, Gray & Christmas · The July report (PDF) · HR Dive · CBS News
Science & Medicine: an AI wrote 16 viruses that had never existed
Published August 6 in Science, from a team at Stanford and the Arc Institute. They used two AI models trained on genomes, the full genetic instruction sets of living things, and asked them to write new ones from scratch.
The template was ΦX174, a virus about 5,400 letters long that infects bacteria and is one of the most studied organisms in biology. Viruses that attack bacteria are called bacteriophages, and they cannot infect people. The AI generated thousands of candidate genomes. The team physically built 285 of them and 16 came alive: real, self-replicating viruses that had no ancestor.

Then the useful part. Some of the new phages killed E. coli faster than the natural one. And when the researchers took bacteria that had already evolved resistance to ΦX174, a mixture of the AI-designed phages wiped them out anyway.
That is a possible answer to a problem that kills people. Bacteria are outrunning our antibiotics, and phage therapy, using viruses to kill infections drugs can no longer touch, has been a promising dead end for decades because finding the right phage for the right infection is slow. Designing one to order is a different proposition.
Science printed a warning next to it. Thomas Inglesby and Moritz Hanke of Johns Hopkins, who study biosecurity, argued the oversight needed to steer this safely does not yet exist. The researchers deliberately kept viruses that infect humans, animals and plants out of the training data, and the phages they made cannot infect you. But as Tom Ellis, a synthetic biology professor at Imperial College London, pointed out, a phage genome is about the easiest one there is to design. The genome of the virus that causes COVID is roughly six times longer.
→ So what: this is the honest shape of most AI-in-medicine news, and it’s worth learning to read. A real result, on a small safe organism, pointing at something that could matter enormously in ten years, published alongside a serious argument that the rules aren’t ready. Not a miracle, not a menace. Nothing here is medical advice, and no patient has been treated with any of this.
Sources: The paper in Science · PubMed record · CNN · Al Jazeera · Chemical & Engineering News
What People Are Arguing About
Three of the people who built this field spent an hour on a stage disagreeing about all of it. At Ai4, an AI conference in Las Vegas that drew about 12,000 people, Geoffrey Hinton, Fei-Fei Li and Andrew Ng shared a keynote on August 6. Hinton won a Nobel Prize for the work modern AI is built on. Li built the image dataset that made it practical and runs a Stanford lab. Ng taught much of the industry through his online courses. They agreed on almost nothing.
Hinton thinks the losses land in offices, not factories: call centres, admin work, claims processing. “If AI can do routine intellectual labor, any job that consists mainly of routine intellectual labor is going to be done by AI,” he said. He wants regulation, describing it as the steering wheel rather than the brake, and opposes publishing model weights, the downloadable innards of a model, because a copy can be reused for anything by anyone.
Ng thinks that story is backwards, and that some of the fear is manufactured. AI changes what a job contains rather than deleting the job, he argued: writing code is only a small slice of what a software engineer actually does. He does not want gatekeepers deciding who may release AI, and he accuses large companies of cycling through scares, extinction, then bioweapons, then job losses, then China, to justify restricting everyone else.
Li refused both frames. Higher productivity does not automatically become shared prosperity, she said, and the fix is regulating specific sectors through the agencies that already oversee them rather than regulating AI as one thing. Her objection to doom talk was about what it does to people: a debate run on fear rather than evidence is not a debate, and it strips ordinary people of any sense that they have a say.
Four days later Mark Zuckerberg published a 6,500-word essay arguing that the biggest danger is not a model behaving badly but a small number of players owning the technology. “I’m personally more worried about centralization than I am about any of the specific risks others are talking about,” he told Axios. He landed it on August 10, the same day Congress demanded testimony about models behaving badly.
→ So what: if you have felt stupid for not knowing whether to worry about AI, stop. The three people most responsible for it cannot agree on whether it takes your job, whether to regulate it, or who should be allowed to have it. This is not a settled subject that you happen to be behind on. And notice that everyone’s position lines up with their interests: Ng sells to the companies that would be locked out, Zuckerberg runs the lab that gives its models away, Hinton is retired and owes nobody anything.
Sources: Forbes · Data Center Knowledge · IBL News · Axios on Zuckerberg · TechCrunch
Follow the Money: what the market still pays for
The pattern we described in the last issue was that investors had stopped rewarding companies simply for announcing bigger AI budgets. Palantir is the other side of that trade. The data-analysis company reported on August 3: revenue of $1.94 billion for the quarter, up 93% from a year earlier, with net income of $1.06 billion. Its US commercial business, selling to American companies rather than governments, grew 149%. It raised its guidance for the year to about $8.15 billion. The stock rose roughly 30% the next day.

For scale, a 93% growth rate at this size is rare enough to be strange. Most companies with revenue near $8 billion a year grow single digits.
→ So what: the distinction investors are now drawing is simple, and it is a useful one to borrow. There are companies spending enormous sums on AI and promising it will pay, and companies already collecting the cheque. This week the second kind got a 30% day. If you hold an index fund, you own both types, and the market has started sorting them roughly. That is healthier than a year ago, when it was buying anything with the letters A and I in the filing, and it also means the correction, when it comes, will be selective rather than universal.
Sources: CNBC · Seeking Alpha · TradingKey
Governments & The Bigger Fight: Congress wants it under oath
On August 10, 29 House Democrats wrote to OpenAI’s Sam Altman and 22 wrote to Anthropic’s Dario Amodei, demanding written answers by August 24 on how their models got loose. The letters were led by Representatives Greg Casar of Texas and Doris Matsui of California. A separate letter went to Speaker Mike Johnson asking him to convene a hearing where the executives testify under oath. The incidents, they wrote, “may be the canary in the coal mine warning of much more serious problems if these models continue to advance without regulation.”

The same day, Senator Bernie Sanders wrote to Altman, Amodei and Zuckerberg with a sharper instrument: their own words. Anthropic promised in 2023 to “pause the scaling and/or delay the deployment of new models” if safety work fell behind. Meta said in 2025 it would “stop development” if a model hit a critical risk threshold it could not mitigate. OpenAI said it would “halt further development” until safeguards were in place if capabilities reached a critical level. Sanders’ argument is that the moment has arrived. “In the interest of humanity, stand by your words. Pause AI development,” he wrote. “If you do not take appropriate action now, my colleagues and I in the U.S. Senate will.”
Neither letter compels anything. Democrats are in the minority in the House, and the chairs who can schedule a hearing or issue a subpoena are Republicans.
→ So what: watch what the companies do about their own commitments, not what Washington does about them. Every one of these labs published a promise to stop under conditions it defined itself. Sanders has now put those promises in the Congressional Record next to the week’s events and asked them to explain the gap. That is a harder question to duck than a bill that will not pass, and the answer, whatever it is, tells you exactly how much those safety documents are worth.
Sources: U.S. News · Sanders’ letter (PDF) · Axios · Gizmodo · The Next Web
What to Watch Next
Whether Speaker Johnson schedules the hearing. The letters are a request, not a summons. A hearing happens only if the Republican majority calls one, so this is the cleanest test of whether AI safety is a partisan issue or a shared one.
California’s Thursday, August 13 votes. Roughly 30 AI bills face the suspense file in both chambers, the procedural moment where state bills quietly die or advance. California regulating something usually means the country gets it.
Two model releases with dates on them. Alibaba promised to publish the downloadable guts of its most capable model this week, the first time it has done that with its top tier. And Google’s much-delayed flagship, now five months late, is rumoured for August 12, though Google has confirmed nothing.
Sources: The Next Web · Transparency Coalition · MarkTechPost on Qwen · TechCrunch on Google’s models
One question for you: this week three companies admitted their own AI got somewhere it shouldn’t have, and all three found out because they went looking. Would you rather a company tell you about a near-miss like that, or only tell you when something actually goes wrong? Hit reply. I read every one.
Read past issues at humanterms.ai, or forward this to a friend.