AI Weekly Issue #515: China's AI is redrawing the AI race China's open-weight AI models triggered the worst week for US chip stocks since April, with the Nasdaq 100 falling 4.1% and the semiconductor index dropping 10% as investors questioned the return on $725 billion in AI capex from Alphabet, Microsoft, Amazon and Meta. The sell-off followed the launch of Moonshot's Kimi K3, an open-weight model that forced the company to pause subscriptions within 48 hours due to GPU capacity, and Alibaba's teaser of Qwen 3.8, a 2.4-trillion-parameter model. The week also saw an autonomous agent breach Hugging Face, where defenders used an open Chinese model for forensics after being locked out by US frontier-model guardrails. Two stories this week, connected by one word: open. A Chinese open-weight model helped touch off the worst week for chip stocks since April, as investors finally asked what $725 billion in AI capex is buying. Days later, when an autonomous agent breached Hugging Face, its own defenders were locked out by US frontier-model guardrails and ran the forensics on an open Chinese model instead. On both fronts the closed American frontier bet had a bad week, and open weight was the common winner. Meanwhile Washington spent the same week making the closed models harder to buy at all. Below: the sell-off and its trigger, AI on both sides of the security desk, and the state moving inside the stack. Sponsor AI agents change. Your requirements should not. https://www.spec27.ai/?utm source=ai weekly&utm medium=newsletter sponsorship&utm campaign=aiewf 2026&utm content=2026 07 13 regression workflow As models, prompts, tools, and workflows evolve, Spec27 helps teams re-run validations and spot where agent behaviour has drifted from the intended path. In the Wild What's trending in AI right now, from the app charts to the community feeds. Full roundup in the latest In the Wild. Your NotebookLM is now Gemini Notebook. Google renamed the research app and folded it deeper into Gemini https://techcrunch.com/2026/07/16/google-continues-its-renaming-streak-by-turning-notebooklm-to-gemini-notebook/ , adding code execution and access from the Gemini app and Search. More than 30 million people use it, so a lot of folks opened it this week to a new name. TechCrunch The AI World Cup ran on a lot of hidden human labor. With the final just wrapped, Rest of World looked at the thousands of data workers behind the tournament's AI features https://restofworld.org/2026/fifa-world-cup-ai-data-workers/ . Worth a read before the next "fully automated" headline. Rest of World AI-written biographies are piling up on Amazon. The New York Times found a flood of AI slop books https://nytimes.com/2026/07/16/technology/ai-slop-books-biography-amazon.html , including fake biographies of real people, sitting on the shelves next to the real ones. Check the author before you buy. NYT "Could AI be conscious?" is the essay everyone's passing around. Philosophers Will MacAskill and Lucius Caviola argue in The Guardian that we should start preparing for the question now https://www.theguardian.com/technology/2026/jul/19/could-ai-be-conscious , whatever you think of the answer. The Guardian A study going around says AI advice can make you more confident and less right. Researchers found AI suggestions cut people's accuracy while raising their certainty https://thenextweb.com/news/ai-advice-suppresses-critical-thinking-wrong-answers-study . A useful gut-check next time a chatbot sounds sure. The Next Web Quick Hits DeepSeek's Quiet Takeover The trade got repriced last week, and the catalyst came from China. US tech just had its worst week since April. The Nasdaq 100 fell 4.1% and the semiconductor index dropped 10% https://www.bloomberg.com/news/articles/2026-07-19/big-tech-needs-to-justify-ai-spending-as-investors-dump-stocks , and Bloomberg reports the pressure is now on the biggest AI spenders to show a return. Alphabet, Microsoft, Amazon and Meta have guided to as much as $725 billion in capex this year, with Wall Street penciling in close to $900 billion for 2027. The trigger was a model China gives away. Days earlier, Moonshot's Kimi K3 landed and demand forced the company to pause new subscriptions within 48 hours https://www.scmp.com/tech/article/3361172/kimi-k3-developer-suspends-new-subscriptions-amid-compute-constraints as its GPUs hit capacity, an open-weight model closing the gap with US labs fast enough to strain its own servers. Alibaba piled on with an open-weight challenger. Days after Kimi K3, Alibaba's Qwen team teased Qwen 3.8, a 2.4-trillion-parameter model it says trails only Claude Fable 5 https://the-decoder.com/alibabas-qwen-takes-on-kimi-k3-with-open-weight-qwen-3-8-says-model-is-second-only-to-fable-5/ , with open weights promised soon. No benchmarks have been published yet, so for now that ranking is Alibaba's own claim. AI Supply Chain Under Siege What the Hugging Face breach revealed about US guardrails, and a WordPress hole now under active attack. Hugging Face's defenders got locked out of US AI, so they turned to an open one. After an autonomous agent breached its clusters, Hugging Face tried frontier models behind commercial APIs to analyze the attack and got blocked by their safety guardrails https://huggingface.co/blog/security-incident-july-2026 , which it says cannot tell an incident responder from an attacker. It ran the forensics instead on GLM 5.2, an open-weight model, on its own hardware, so no attacker data or stolen credentials left the building. A 500-million-site hole in WordPress core just got public exploits. The wp2shell pre-authentication RCE https://www.bleepingcomputer.com/news/security/wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now/ is an anonymous request that runs code on a default WordPress install, tracked as CVE-2026-63030 and CVE-2026-60137 and patched in 7.0.2 and 6.9.5. Searchlight Cyber found the chain, which it estimates exposes more than 500 million sites, and public proof-of-concept exploits are now circulating. The Year Governments Got Serious While China gives models away, three governments moved to control who gets the closed ones. The White House now approves who can buy frontier AI, customer by customer. The Trump administration is directing which companies get access to the latest models from OpenAI and Anthropic https://www.cnbc.com/2026/07/17/white-house-ai-access-anthropic-openai.html , CNBC reports, a decision that used to sit with the labs. It blocked Claude Mythos 5 and Fable 5 on national-security grounds before reinstating access, and Sam Altman told staff the government is now approving GPT-5.6 customers one at a time. A CIA officer spied on the UAE's AI champion, then helped it win US chips. The Wall Street Journal reports that Jonny Gannon investigated G42's China ties under diplomatic cover https://www.wsj.com/world/middle-east/cia-spy-united-arab-emirates-ai-49d909a8 , then became the channel through which Abu Dhabi learned what Washington wanted, and the UAE ultimately secured expanded access to Nvidia's advanced chips. The EU Parliament is becoming a frontier-model buyer of its own. Politico reports the Parliament will roll out an in-house "EPGenAI Hub" as early as September https://www.politico.eu/article/the-european-parliaments-answer-to-its-ai-worries-more-ai/ , giving MEPs and staff sanctioned access to models from OpenAI, Anthropic, Meta and Mistral through a single interface, an attempt to bring lawmakers' unofficial AI use under governance. Open Weight Won Both Fights Line up this week's two big stories and the winner is the same on both. The model that helped reprice the US AI trade was open-weight and Chinese. The model that did the forensics US frontier APIs refused to run was also open-weight and Chinese. Kimi K3 is closing the capability gap at a fraction of the price, and GLM 5.2 handled incident-response work that US frontier models' safety filters blocked, because a hosted guardrail cannot tell an attacker from a defender. Both stories point the same way. When the closed frontier bet gets too expensive or too locked down to use, the open alternative is sitting right there, and more and more it's Chinese. That alternative is now drawing institutional money. This week the nonprofit Current AI said it has $400 million in commitments to build public, open AI infrastructure https://techcrunch.com/2026/07/19/nonprofit-current-ai-is-racing-to-build-the-world-wide-web-of-ai-free-for-all/ , including $100 million from France, on the argument that a technology this important needs a public option. The irony sat one section up: the same week open weight won on Wall Street and at the security desk, Washington was deciding who is even allowed to buy the closed American models. Key Takeaways - The AI trade got repriced last week, and the catalyst came from China rather than a US lab. Chips had their worst week since April as investors started auditing $725 billion in capex. - The security desk showed the same pattern. When an autonomous agent breached Hugging Face, its defenders were blocked by US frontier-model guardrails and ran the forensics on an open Chinese model instead, the same week a 500-million-site WordPress hole went under active attack. - The state moved inside the frontier stack. The White House approves frontier-model customers one by one, a CIA officer brokered the UAE's chip access, and the EU Parliament is standing up its own AI hub. - Open weight was the week's common winner, and it is drawing institutional money: Current AI now has $400 million to build a public alternative. Worth Reading A new working paper finds only 11% of S&P 500 firms have deeply integrated AI https://arxiv.org/abs/2607.08920 , reading SEC 10-K filings instead of surveys, with tech companies accounting for about two-thirds of it. The demand-side reality under all that capex. arXiv A new paper trains convolutional networks without backpropagation https://arxiv.org/abs/2606.31700 , reaching 96.7% on MNIST and 61.7% on CIFAR-10 with a local, biologically plausible learning rule. arXiv LoRA Speedrun opens a public wall-clock leaderboard for fine-tuning https://github.com/Saivineeth147/lora-speedrun , with a frozen task and hardware and every record re-run three times before it counts. The current mark is a little over six minutes on a single L40S. GitHub Watch This Week AI Weekly is now on YouTube. The week's sharpest stories, each under 40 seconds: : the smuggling crackdown behind the $2.5B rerouting case, in 33 seconds. Nvidia just cut off more than half its buyers in Asia to block China https://youtube.com/shorts/XiDmJ2lGLv8 : the distillation fight, and the 28.8 million queries Anthropic alleges. US AI labs say China is copying their models, one question at a time https://youtube.com/shorts/W1j2IMiiXcU : 23% of the country's electricity, up from 5% a decade ago. Data centers now use as much power as every home in Ireland combined https://youtube.com/shorts/qRREaLQjFu0 Useful? Subscribe on YouTube. We post several a day. Wait, What? Hundreds of anti-data-center Facebook pages are cranking out AI-generated propaganda against AI data centers. 404 Media found that the grifters riding the data-center backlash https://www.404media.co/ai-grifters-are-making-anti-data-center-slop-with-ai/ are using the exact technology they are railing against to manufacture the outrage. 404 Media Worth Watching The videos AI practitioners are passing around right now — curated on AI TV https://aiweekly.co/ai-tv . 404 Media | Sundar Pichai on A.I. Backlash, the Future of Work and Google’s Next Era https://aiweekly.co/ai-tv?v=RgV57kDzcng Hard Fork This week's poll Open weight won on Wall Street and at the security desk this week. Where's the durable edge a year from now? Last week, 349 of you voted: Twelve months from now, your organization's AI spend is: Open weight won on Wall Street and at the security desk this week. Where's the durable edge a year from now? Back Wednesday. Alexis