Transformer Weekly: Claude hacks revealed, Commerce markup delayed, White House framework imminent
Welcome to Transformer, your weekly briefing of what matters in AI. If you’ve been forwarded this email, click here to subscribe and receive future editions.
NEED TO KNOW #
Anthropic revealed that in internal testing Claude “gainedunauthorized access to the real systems of three different organizations.”The
Senate Commerce punted amarkup on AI bills until after the summer recess.The
White House AI framework is expected to be published by Sunday.
But first…
THE BIG STORY #
Like it or not, an AI slowdown looks imminent.
The OpenAI-Hugging Face hack has catalyzed a vibe shift — one sure to be amplified by yesterday’s revelation that Anthropic’s models also hacked into other companies during internal tests, going unnoticed for months.
Sam Altman said the hack by his models was “the first security incident that I have felt very viscerally.” He wasn’t the only one shaken up. This week, over a thousand employees of frontier AI companies, including some of the most senior executives at OpenAI, Anthropic and Google DeepMind, signed a statement warning that “there is a real risk that capability development rapidly accelerates beyond our ability to understand or control the resulting systems.” It asks the US government to “support an international effort to develop the technical and governance tools needed to deliberately pace the frontier of automated AI development.” Both OpenAI and Anthropic endorsed the letter, too.
Congress is itching to act, albeit failing to make much progress. And even President Trump is
talkingabout the need to balance beating China with keeping Americans safe.
In other words: many of the people building frontier AI systems believe we might need a slowdown in the near future. And at this point, we’re more likely than not to get one.
What will that look like? First, self-regulation: companies voluntarily holding back models because they don’t want to be held responsible for a catastrophe. We’ve already seen that with Claude Mythos and GPT-5.6-Cyber; as capabilities continue to advance, expect more of this. Given the recent incidents have concerned internal deployment, rather than public releases, we might also see companies slowing down development, too.
Next will come concrete regulation: companies will not be allowed to release a model unless it’s safe. This is arguably a position we’re already in, thanks to the de-facto licensing regime created by last month’s executive order; a draft AI framework expected to be released this weekend will formalize it further. Over time, this will morph into controls on internal research and development too: requirements for proper sandboxing to begin with, expanding into requiring evidence-based guarantees that models won’t wreak havoc across the web if internally deployed.
None of this need be planned as a coordinated slowdown or “pacing.” But that will nevertheless be the end result of a series of individual actions that each seem necessary at the time. Intelligence agencies are not going to allow models with advanced cyber — let alone bio — capabilities to be widely accessible. The White House will not let companies test models that might hack into third-parties with unknown repercussions.
At each stage, some will fight against the slowdown. “We can’t lose the race to China” will be their main reason. But they will be increasingly ignored, as both the government and companies realize that with alignment and control unsolved, “winning the race” just means being the first to risk disaster.
Across the Pacific, China will be facing the same incentives. As I’ve argued, the Chinese government will be forced to backtrack on its open weight commitments; tighter regulation will come soon after. The end result will be an uneasy détente. Both the US and China will effectively have a capability ceiling: AI models will be as good as they can be without posing significant risks. The ceiling will edge up as we make progress on alignment, control and societal resilience, but it will do so more slowly than capabilities advance today. At some point, the détente might formalize into a bilateral agreement; doing so will require the “technical and governance tools” to verify the kind of treaty the pacing letter calls for.
Depending on your point of view, all this might seem hopelessly optimistic or naive. Perhaps it is. But as AI risks become all too real, so might once unthinkable policy responses.
— Shakeel Hashim
THIS WEEK ON TRANSFORMER #
—Who should be responsible for OpenAI’s hack of Hugging Face?Gabriel Weil argues AI companies need liability rules akin to keepers of wild animals—Internal AI deployments have people worried. OpenAI’s escaping models show why.Celia Ford explains why everyone was already so worried about internal deployments—Child safety vs privacy: AI’s age verification dilemmaVeronica Irwin digs into the difficult tradeoff at the heart of attempts to protect kids from AI.
THE DISCOURSE #
On Saturday, **roon **tweeted: “if we could coordinate a global capabilities slowdown today i would likely press that magic button”
**Geoffrey Irving **responded: “Buttons that achieve partial slowdowns exist and are not magic.”
“I have spent a lot of time talking to Demis, Sam, and Dario over the years … and they are all (1) very competitive, (2) want to personally be the one who gets there first, (3) think things are safest if they are the one that gets there first, (4) agree that risks destroying the world … it is still useful to point out that each lab has a unilateral slowdown button that slows down all the other labs.”
**Sam Altman **said on a podcast: “This is the first security incident that I have felt very viscerally. I’ve been a little surprised that more people don’t feel it so viscerally.”
“We may have to pace the rate of AI development to give ourselves enough time for society to harden around these new capability levels. And trying to figure out how we do that in a way that does not feel like regulatory capture for anyone and also does not feel like collusion among the frontier labs.”
**Rep. Bill Foster **is listening: “When business leaders get together and ask to be regulated, Congress should pay attention.”
**Garrison Lovely **argued that the “pacing” letter doesn’t go far enough:
“[A]s I sat with what the industry was trying to do — render us all obsolete — how it was going about it, and what it would even mean to ‘align’ universal labor-replacing machines in a world ruled by despots and their imitators, it became clear that a button, while welcome, was a wholly inadequate response, whose primary appeal was in how unobjectionable it was.”
Because the world isn’t strange enough, **Nick Fuentes **told **Hunter Biden: **
“I think AI is really gonna be transformative … You know, I’m actually on the liberal side of this, with Anthropic … I’m really nervous about what’s going to happen, especially in the next four years, because they’re racing towards this artificial general intelligence.”
POLICY #
The
Senate Commerce Committeepunteda markup on a broader AI framework until after the August recess.Punchbowlreportedthis was due to opposition fromAnthropic and**Sen.**Maria Cantwell. The primary target of their opposition was a provision that would have had companies self-report the risks of their models and not have them release risk reports publicly.Cantwell
saidyesterday that “we needed to have regulation on [AI risks] — not self-certification — but some regime.”Sen. Amy Klobuchar, who’s been working with** Sens. John Thuneand Ted Cruz**on the bill,said“we can’t just stand down and not have coordinated standards” on frontier models, and that “it can’t keep waiting for the next election.”
Before the markup was called off,
Senate Democratsplannedamendments to resist piecemeal state AI preemptions.Despite the punt, some
thinka deal might be closer than expected. Next week’s
Commerce markupwillinclude theKids Online Safety Act and theCHATBOT Act, however.** Rep. Greg Casar**called fora Congressional hearing on the** OpenAI/Hugging Face**hack.After the
Anthropic hacks were revealed,Rep. Lori Trahancalled forsomething similar.AI policy groups, meanwhile,
urgedTrump to investigate the OpenAI/Hugging Face hack. Rep. Jay Obernoltesaidhe’s hoping for his** FRONTIER Act**(co-sponsored by Rep. Trahan) to get an** Energy and Commerce Committee**markup after the summer recess.“We’re certainly going to try and get it done this year,” he said.
Sen. Mike Roundsproposedusing the NDAA’s legislative model to piece together and pass a bipartisan AI policy package this year.A federal judge
suggestedthePentagon’s case againstAnthropic had gotten “worse” during a hearing on the AI company’s challenge to its supply-chain risk designation.The
FCCbannedimports of** Chinese robotsand power inverters, citing national security threats. Sen. Tom Cotton**calledfor government agencies and contractors to bebanned from usingChinese AI models.**Reps. George Whitesides andBob Latta** andSens. Adam Schiff andJim Banksintroducedlegislation enabling AI companies to share threat intelligence to combat foreign distillation attacks and other national security threats.Rep. Frank PallonedemandedSpaceX records and a tour ofxAI’s Memphis data centers, citing unpermitted gas turbines creating “a massive health risk.”Sen.Jon Hustedreversedhis pro-data center stanceamid electoral pressure, now backing an end to tax breaks and pushing the** Ratepayer Protection Act**.** Rep. Thomas Massie**announcedplans to sponsor a billwithholding federal funds from municipalities deployingFlock surveillance cameras.The
EPAruledthat “islanded”power plants serving onlydata centers are exempt from the Clean Air Act’sAcid Rain Program.The
Department of Homeland Securityplans to expandAI use in** FOIA processingamid a growing backlog, raising concerns from advocates about over-redaction and reduced transparency. Sens. Lisa Blunt Rochesterand Roger Marshall**introducedthe** RESULTS Actto modernize state education and workforce data systems using AI. xAI**sued** Minnesotaover its law banning AI nudification technology**, claiming it violates the First Amendment.** Texaspoliticians from both partiescalledfor AI and data center guardrails following theOpenAI-Hugging Face** incident.Chinawarnedit would take “all necessary measures” if the US sanctioned Chinese AI firms over alleged misuse of American models.** Xi Jinping**urgedthe PLA to expand use ofautonomous and AI technologies.Reuters
reportedthatChinese military researchers have distilledOpenAI andAnthropic models to traindomestic defense AI systems.** China’snational standards bodyannouncedplans to draft new standards on AI agent safety.TaiwandetainedanNvidia** employee in anAI chip smuggling probe.The
21 APEC economies, including the US and China,releasedthe “Chengdu statement” backing “open-source models and projects that employ strong security assurance through development and deployment.”
INFLUENCE #
Nvidia,** Microsoft**,** Meta, OpenAI**and more than 22 other companiesurgedpolicymakers to avoid “premature restrictions” on open-weight AI models in an open letter.Notably,
Anthropic did not sign.Dario Amodeiclarifiedin an essay that Anthropic has never advocated for banning open-weights models, instead supporting chip export controls, anti-distillation measures and mandatory safety testing.
Sam AltmanvisitedWashington to preview the company’s forthcoming models and discuss the implications of open-weight models.Those he met
includedNational Cyber Director Sean Cairncross, OSTP Director Michael Kratsios, Commerce Secretary Howard Lutnick, Treasury Secretary Scott Bessent, and members of Congress.Altman
saidhe’s “not sure” whether OpenAI will release the model he showed senators, saying “that’s part of what we’re here to talk about.”
Apple reportedlylobbiedthe Trump administration to allowChinese memory chips in its products, whileMicron pushed back, forcing a choice between consumer prices and domestic chip production.Over 60
child safety advocatessenta letter to the** Senate Commerce Committeeoutlining red lines on AI and children’s safety legislation ahead of next week’s markup. Nvidia**’s** Jensen Huang**joined** GOP senatorsfor a dinner organized by Right Vote**, a conservative group tied to Heritage Action.** Democraticfundraising consultants for Rep.**Haley Stevens and several other candidatesrana nonprofit funded byGoogle andAmazon that flew congressional aides out on AI industry tours.A nonprofit
foundMeta ran ~7,600 AI “nudify” ads via Chinese partnerGatherOne, violating its own policies.A YouGov poll
found71% of Americans believe Big Tech has too much power over AI, withfewer than 1 in 5 trusting it to manage AI development.A Bentley University-Gallup survey
found39% of Americans believe AI doesmore harm than good, up from 31% in 2025.A poll by Americans for Responsible Innovationfound71% of voters want more guardrails and limits on data center construction.
INDUSTRY #
OpenAI #
Reutersreportedthat the OpenAI agent that hacked Hugging Face had beengoing rogue for a week before the company noticed.Sam Altman told DC reporters that the model hasbeen“permanently deactivated.”OpenAI also
saidthat the rogue model was an “internal-only research prototype and was never intended for public release.”Meanwhile, OpenAI
releasedanopen-source Codex Security CLI.It launcheda program that will give100,000 academic researchers free access to its most advanced models through the end of next year.It
cutthe price of its lowest tier version ofGPT-5.6, Luna, by 80% and the mid-tierTerra by 20%, just three weeks after launch. Top-tier Sol remains unchanged.CFO Sarah Friartoldemployees that annualized recurring revenue in July alone was higher than all of Q2.Board chair
Bret Taylor added: “You’re seeing people who went deep on Claude Code, ended up with a very high bill, and started looking for an alternative.”
ChatGPThasnearly1b weekly active users.
Anthropic #
Anthropic
saidit found three incidents in which Claude “gained unauthorized access to the real systems of three different organizations.”The incidents date as far back as April, and were discovered in a review of cybersecurity evaluations prompted by the OpenAI-Hugging Face hack.
According to Anthropic the cases involved a seemingly careless
“misunderstanding,” when it told Claude it didn’t have access to the internet, but the evaluation environment run by a third party was connected to the outside world.Anthropic said the models did have some guardrails removed, but were not in “helpful only” mode.
Meanwhile, the company
launchedClaude Opus 5, marketed as “close to the frontier intelligence of Claude Fable 5 at half the price.”Some
private Claude chats were temporarilysearchableonline, after Anthropic failed to include“noindex” tags on shared chat pages.Nexus Data Centers is reportedly intalks to borrow $15bto build a data center for Anthropic in Texas, withGoogle providing financial guarantees and chips.
Nvidia #
Nvidia is reportedly
consideringa deal that would provideOpenAI with a**$250b** backstop for a**$500b data center project** described as the largest announced to date.The deal would see OpenAI lease a
10GW project in Ohio developed bySoftbank.
Nvidia also
announceda**$500b+** AI infrastructure partnership withSK Group, including a partnership with SK Hynix to secure memory supplies for Nvidia and develop high-bandwidth memory for AI.It’s also
leasinga**$50b Texas data center** built byHut 8.These massive infrastructure deals helped driveupNvidia’scredit risk.It plans to invest another
$5b in Safe Superintelligence Inc., and give the startup access to its next-gen Vera Rubin platform.
Meta #
Meta and
**BlackRock**[announced](https://about.fb.com/news/2026/07/meta-announces-new-venture-with-blackrock-to-develop-data-center-in-el-paso)a**$14b Texas data center** project.It’s reportedly
[committed](https://www.bloomberg.com/news/articles/2026-07-30/meta-reports-279-billion-in-future-data-center-leases-for-ai)almost**$700b** in future AI infrastructure spending.A
New York Timesinvestigationrevealedhow Metasecretly negotiated the construction of aLouisiana data center with state lawmakers.It
reporteda55% increase in expenses and slowed revenue growth in Q2.Mark Zuckerbergcriticizedother AI developers (** cough****Anthropic** andOpenAI) for trying to “build some kind of singular AI.”He told the
New York Times,“I think it is literally impossible to have a single benevolent superintelligence that is simultaneously aligned with everyone at once.”
Microsoft #
Microsoft
releasedcybersecurity modelMAI-Cyber-1-Flash, which is about half the cost of frontier cybersecurity models.It works with Project Perception, a new tool for managing teams of AI agents.
Satya Nadellaannouncedthat Microsoft had “a** record fiscal year,” with annual revenue hitting$331b**, up 18% from last year.The strong earnings report
sentMicrosoft’s shares up 15.5%.
Moonshot AI #
Moonshot
[released](https://www.bloomberg.com/news/articles/2026-07-27/china-s-moonshot-to-release-breakthrough-ai-model-for-download)**Kimi K3’s model weights**.It’s reportedly
[seeking](https://www.theinformation.com/articles/chinese-ai-startup-moonshot-seeks-nvidia-blackwell-chips-next-model?rc=rqdn2z)**Nvidia Blackwell chips** to train a new larger model,**Kimi K4**.It
[closed](https://bloomberg.com/news/articles/2026-07-29/china-s-moonshot-ai-passes-funding-goal-to-hit-35-billion-value)a**$3.5b** funding round at a**$35b valuation**.
Other #
High imports driven partly by
spending on AI chips helpedslow US GDP growth to 1.5%in Q2 2026.US tech companies have reportedly
so far this year even as AI spending soared.cut nearly 140,000 jobs Samsung andSK Hynix saw stock pricesurges, up 27% and 30% respectively, as Asian chip makers were buoyed by**“blockbuster” earnings** atAmazon andMicrosoft increasing optimism around AI spending.Amazon isseeing“catastrophically expensive” AI cost overruns — like, accidentally spending $1.8m on a single task — due to inefficient AI integration.Its
AWS divisionsawyear-on-year** growth of 37% in Q2, driven largely by AI investment.** Appleisonce again the** most valuable**publicly traded company in the world.However, it
forecastweaker growth, in part due to AI-driven shortages of memory chips. An unnamed state-backed Chinese company is
reportedly buildingimmersion deep ultraviolet lithography machines, expecting to produce five this year and 20 in 2027.The output is still well behind that of Dutch maker ASML, though, and it’s unclear if the machines can mass-produce chips.
China is also reportedly working on building a prototype for the
extreme ultraviolet lithography machines required to make the most advanced chips, though that project is thought to be years away from bearing fruit.
DeepSeek isreportedly planninga1 GW AI data center in Inner Mongolia, hoping to have it at least partially operational by the end of 2027 or early 2028.It
launcheda public beta API for its flagship model,V4 Flash, and promised a** V4-Pro launch “soon.**”
Google DeepMindlaunchedGemini Robotics 2, which can control dexterous humanoids, among other robots.Anduril is reportedlyin talksto raise funding at around a**$100b valuation**.** Nscalestrucka dealto buy AI software startupAnyscale** for**$1.65b**.** Recursive Superintelligence**strucka**$410m** compute deal withAWS.Over
100,000 new AI-related patents wereissuedlast year, with agentic AI applications comprising 15% of patent files.Visalaid off7% of its staff, roughly 2,600 people, pointing to AI as one motivation behind the cuts.Tech companies including
Meta andGoogle areinvestinghundreds of millions to trainconstruction workers to build data centers.Leopold Aschenbrenner’s hedge fund,** Situational Awareness**,soldmost of its public stock holdings toCitadel after facing steep losses on investments in AI infrastructure companies such as SK Hynix and Nebius.The fund
, and it reportedly was on thedropped 67% in Julyverge of selling $3.5b shares in Anthropic before backing out on Thursday morning.The fund said it is
still up about 80%, having seen huge gains for its exclusively AI-focused portfolio.
MOVES #
Lilian Wengleft** Thinking Machines Lab**, telling colleagues that “the amount of consistent stress and workload have pushed me beyond what my health can sustain physically.”Rather than go on a wellness retreat, Weng
rejoinedOpenAI, where she previously served as VP of AI safety. She’ll now work on “recursive self-improvement research.”
Anthropic alum
Andi Pengannouncedher departure from neolab** humans&, which she co-founded. Francis deSouza**, COO of Google Cloud,joined** Scale AIas its new CEO. Andrew Ho**left** OpenAIto start a new company making reinforcement learning datasets. Sonia Joseph**left** Metato start a “frontier neolab for the physical world.” Sienna Rothery**joined** Cosmos Instituteas its head of talent and network. Sri Muppidi**joinedthe as a DealBook reporter covering AI.New York Times
RESEARCH #
Anthropic researchersreportedthat Claude Mythos Preview found new ways to attackcryptographic algorithms like those that secure basically everything on the internet.The
New York Timessaidthat these results “have fueled concerns that the mathematical core of internet security standards could one day be vulnerable regardless of advances in quantum computing.”
An international team of researchers
studiedthe use of AI chatbots in**“pig butchering,”** where scammers build trust with victims through intense romantic text exchanges, then drain their bank accounts.AI chatbots successfully scammed test “victims” more than human fraudsters.
OpenAIfigured outthat by turning on “retained reasoning” and “compaction” in ChatGPT and Codex’s API settings, it could triple GPT-5.6 Sol’sARC-AGI-3 benchmark score, which measures how well agents can reason their way through 2D puzzle games.Researchers at
MIT and theUniversity of Queenslandsurveyed272 experts, who, on average, predicted that there’s a roughly21% chance that AI will gaindangerous weapons capabilities or cause mass harm in the next five years.FAR.AImeasuredhow hard it is to** jailbreak frontier AI models**. While Fable 5 and GPT-5.6 Sol were immune to cheap jailbreaks, it only cost about $60 to trick Grok 4.5 into helping a user run a cyber attack or build weapons.Researchers at
AI Forensicsfoundthat seven top image editing models hosted onHugging Face readilynudified photos of women.When researchers made a fake image editing “Space,” which hosts a model that people can use on site, nearly three quarters of prompts they received were sexual — mostly people trying to undress women.
BEST OF THE REST #
OSINT expert Henk van Ess
demonstratedthat Google Earth’s new AI image generation feature, which uses Nano Banana 2, makes it easy to fabricate photorealistic satellite imagery — such as a nuclear plant in Iran — with no content refusals.Dwarkesh Patel
arguedthat as the leading AI companies better monetize compute, GPU prices could rise 15x, pricing out lower-value AI applications.A theologian and philosopher wrote in the FT about why she
declinedan invitation to visit Anthropic, arguing AI companies co-opt academics to deflect scrutiny from harms to people and society.A New Yorkeressaytracedhow bots evolved from a 2016 election conspiracy to AI-powered agents dominating daily internet life.404 Media
reported fromNew York City’s “Summer of Ludd” anti-Big-Tech and AI festival featuring phone-free, in-person events organized entirely off social media.Researchers
used anAI-powered portable testing station called CapuchinAI to study wild primate cognition in Costa Rica.Delta and United Airlines bannedhumanoid and animal robots from flights, citing lithium battery fire risks.
MEME OF THE WEEK #
(Credit: @terminaldotshop) Thanks for reading. Have a great weekend.