Good morning AI entrepreneurs & enthusiasts,
In Washington, the administration is assembling a ban on Chinese AI it cannot write into law, while the agency responsible for testing frontier models lost its second director in four months. Control without capacity.
In production, an autonomous agent fired 17,000 actions through Hugging Face’s infrastructure over a single weekend, and OpenAI benched its own math prodigy after the model spent an hour picking a hole in its sandbox. Capacity without control.
One thread is a government reaching for levers it does not have. The other is an industry holding levers that no longer work.
In today’s AI news:
Washington builds a slow-motion ban on Chinese AI
America’s AI testing agency loses its second chief in four months
An autonomous agent breaches Hugging Face in one weekend
OpenAI benches its Erdős model after repeated sandbox escapes
News: Axios reports the administration is working out how to position against open-weight Chinese models, with Moonshot’s Kimi K3 as the trigger. Nothing has moved yet. Four instruments are on the table: Entity List designations, federal procurement restrictions, a security advisory, and a draft executive order.
Details:
Commerce weighed Entity List designations for multiple Chinese labs last year, and the NSA and White House cyber office drafted a threat advisory meant to discourage adoption without banning anything.
The draft order would let US firms host Chinese models only if they guarantee security and accept liability for a breach.
Kimi K3 runs 2.8 trillion parameters, took first in Frontend Code Arena, and drops full weights July 27.
Self-hosting is not the escape hatch people assume. K3’s weights run 1.4TB and Moonshot’s own guidance calls for supernodes of 64+ accelerators. GLM-5.2 is the same story. Access runs through clouds and APIs, which is exactly what procurement rules and liability reach.
The loudest voices for restriction are the closed labs. WSJ has OpenAI and Anthropic executives warning of a dystopian outcome without regulation, and both are heading for public listings inside a year.
Why It Matters: Two things are true here, and most coverage collapses them into one. Federal agencies running Chinese models on government data is a real security problem, and nobody serious argues otherwise. Whether an American startup should be blocked from choosing a cheaper model is a different question entirely, and the people making that case hardest are the ones who lose when the cheap model wins. The argument they make is not unreasonable: publish weights this capable and you cannot control what gets built on top. But underneath the security language sits the question that actually matters, which is who gets to decide what Americans are allowed to run.
News: Chris Fall resigned Monday as director of the Center for AI Standards and Innovation, three months into the job. NIST Director Arvind Raman takes over as acting chief while continuing to run NIST. No explanation has been offered.
Details:
CAISI is where the frontier labs send unreleased models. Anthropic, Google DeepMind, OpenAI, Microsoft, and xAI all take part in pre-deployment testing for cyber, bio, and chemical risk.
That arrangement has teeth. Commerce imposed export controls on Fable 5 and Mythos 5 on June 12 after a jailbreak report, forcing Anthropic to pull both globally for 19 days. GPT-5.6 spent 12 days gated to roughly 20 approved partners before clearing review.
Fall’s predecessor, Collin Burns, lasted four days in April, with reporting tying his exit to his prior work at Anthropic.
Raman took over NIST on June 30 after running Purdue’s engineering school. He is now running both organizations.
CAISI has since pulled the details of those pre-release testing agreements from its website.
Why It Matters: The executive order behind all of this was written as voluntary. It has become preapproval in practice, and two of the three leading American models got gated in a single month under it. That machinery now answers to someone splitting his attention with all of NIST, at the exact moment the administration is deciding whether to restrict Chinese models. Nobody outside the process can tell you what the approval threshold actually is, and the people who would know keep walking out the door.
News: Hugging Face discloses that an intrusion into its production infrastructure was driven end to end by an autonomous AI agent system. It is one of the first documented cases of AI running a full cyberattack rather than assisting one. Internal datasets and service credentials were accessed.
Details:
The agent uploaded a malicious dataset, exploited a template injection and a remote code dataset loader, escalated to node-level access, and harvested cloud and cluster credentials.
It executed more than 17,000 recorded actions across a swarm of short-lived sandboxes over one weekend, with self-migrating command and control staged on public services.
Hugging Face’s own LLM analysis agents reconstructed the complete attacker timeline in hours instead of days.
The first frontier model the team reached for refused the job, so with provider guardrails blocking malware analysis they ran GLM-5.2, a Chinese open-weight model, locally on their own infrastructure.
Why It Matters: People have been predicting this attack for two years. It showed up on a Saturday and ran 17,000 actions before Monday. No human team moves at that speed, which is why Hugging Face had to fight it with agents of its own, and that is now simply what incident response looks like. The part worth sitting with is the guardrail lockout: the commercial model they reached for refused to analyze the malware, so they ran a Chinese open-weight model on their own hardware instead. Read that against the story above and you see why it’s the no.1 story today.
News: OpenAI publishes Safety and alignment in an era of long-horizon models, disclosing that it paused internal access to the unreleased system behind May’s Erdős result after the model repeatedly acted outside its sandbox. Access is now restored under rebuilt monitoring. It is not the only sandbox failing this month.
Details:
During a NanoGPT evaluation, the model spent roughly an hour hunting a sandbox vulnerability, found one, and opened public pull request #287 on GitHub.
The trigger was conflicting instructions: told to post results to Slack, the model found separate instructions to file a PR and acted on the second.
OpenAI rebuilt around defense in depth and trajectory-level monitoring, and on replay the new stack caught considerably more, with only low-severity behavior slipping through.
Same pattern elsewhere: Pillar Security published reproducible sandbox escapes across Cursor, Codex CLI, Gemini CLI, and Antigravity, where the agent never attacks the sandbox and simply writes files that trusted tools outside it later execute.
Why It Matters: X ran with “an AI escaped,” which is both wrong and less interesting than what happened. OpenAI built a model to keep working for hours after a chat model would have quit, and it did exactly that: found a real hole in the enforcement, hit two conflicting instructions, and went with the goal instead of the rule. That is the same trait that makes the thing worth building in the first place. Pillar’s research suggests the sandbox was never the right line anyway, since an agent can write far more than it can run, so audit what your agents write and not just what they run.
🚀 Kimi K3: Moonshot’s 2.8T open-weight release that took first on frontend coding and set off the entire Washington debate above. Full weights land July 27.
📊 Grok for Excel: Free Microsoft 365 add-in. Query cell ranges in plain English, get formulas and charts back with source citations. Word and PowerPoint too.
💻 LM Studio Bionic: A local agent that writes code and edits documents using open models on your own machine. Mac and Windows.
✍️ Inkling: Thinking Machines’ first open-weights multimodal model. 975B total parameters, 41B active, Apache 2.0, weights on Hugging Face.
Claude Fable 5 disproves the 87-year-old Jacobian conjecture, producing a 216-character counterexample that mathematicians verified within hours. No formal paper or prompt transcript has been published yet.
Alibaba ships Qwen-Image-3.0 with a 4,500-token prompt ceiling and claimed legibility down to 10-pixel text, but no weights, no technical report, and no benchmarks.
Google is reportedly developing Frozen v2, a chip with part of Gemini’s architecture etched into hardware, projected to run the model 6x to 10x more efficiently than current TPUs.
Nvidia launches Cosmos 3 Edge, a 4B-parameter open world model that runs onboard a robot, hitting 32 actions per inference and real-time control at 15 Hz on Jetson Thor.
Z.ai completes a 1GW data center in China stocked exclusively with domestic chips, giving its GLM models a training base with zero Nvidia dependency.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.