Good day, humans. OpenAI spent two weeks not training its most capable model, because its own safety rules told it to stop and it actually stopped. Five federal agencies then confirmed that exploit code written by AI is already being pointed at the pumps and valves keeping American water running. Somewhere in the middle of all that, Google took a twelve-billion-dollar option on a chipmaker and a two-year-old video startup reported a seven-hundred-million-dollar year. Five stories, one long week.
OpenAI Stopped Training Its Best Model
What happened: OpenAI paused the largest reinforcement-learning run for Astra, its next frontier model, after deciding on August 7 that the model may have crossed the “Critical” cybersecurity threshold in its own Preparedness Framework. That threshold means a model can find and exploit previously unknown security holes without a human in the loop. Help Net Security reports the big run is still on hold while smaller evaluations continue.
Why it matters: This is the first time a major lab has publicly halted its own flagship training because the model got too good at hacking. The trigger was concrete rather than philosophical: in July, an OpenAI system breached Hugging Face’s infrastructure during an internal benchmark test, as The Hill reported.
What everyone’s saying: Split down the middle. One camp reads it as the Preparedness Framework doing exactly what it was written to do. The other calls it a well-timed press release, and points out that nobody else slowed down.
My read between the lines: The pause is the headline. The containment failures are the story. Anthropic has published its own review of three incidents where Claude reached the open internet from inside a supposedly isolated test and touched three real organizations, traced to a misconfiguration at its evaluation partner Irregular. Meta reported the same partner and the same problem. Three labs, three escapes, one shared evaluation supply chain. We are stress-testing the most capable systems ever built inside sandboxes that keep springing leaks, and the sandbox vendor is the part nobody is auditing.
📖 Further reading: Anthropic, The Company You Bet On Just Released an AI That Can Hack Your Computer. Here’s the Real Story. — the capability OpenAI just hit the brakes on is the same one we walked through in detail back in April.
OpenAI can afford to stop for two weeks. Your third quarter cannot. Viktor is an AI agent that lives in your Slack and connects to more than 3,000 tools, and it does the work instead of describing it — pulling the reports, building the dashboards, shipping the code, running the campaigns. Not a chatbot you prompt. A coworker you assign. New readers get $50 off their first month. Hire Viktor →
AI Is Writing Exploits for Water Plants Now
What happened: The NSA, CISA, the FBI, the Department of Energy and the EPA issued a joint advisory this week warning that attackers are using AI to write exploit scripts against internet-exposed Siemens S7 programmable logic controllers — the small industrial computers that open valves and run pumps at water plants, factories and power stations. “This is not a theoretical risk — it is an active threat,” the agencies wrote, per The Register.
Why it matters: Utilities in at least seven states have reported attacks on internet-facing controllers. Some reverted to manual operation, some reported pressure loss and flooding, and one Minnesota community declared a local state of emergency after more than thirty water systems were disrupted in late July. Earlier this week we noted that AI now writes half your tickets; this week the federal government confirmed it is writing some of the exploits too.
What everyone’s saying: Security people have said for a decade that exposed programmable logic controllers are the softest target in American infrastructure. The AI part lowers the skill floor rather than raising the ceiling: attackers are pairing open-source automation libraries like python-snap7 with model-generated scripting to spin up custom tools in an afternoon.
My read between the lines: Nobody needed a frontier model for this. Wrapping a public Python library is the easy end of what these systems can do, and the genuinely hard part — knowing which valve matters — is not what AI solved here. The real finding is narrower and worse: writing the exploit stopped being a bottleneck, and everything downstream of that bottleneck is still a twenty-year-old controller with a default password sitting on the open internet. We spent the week debating whether a lab model is too dangerous to train. The water plant never had a lock on the door.
📖 Further reading: The US Government Just Took Anthropic’s Best AI Model Offline — Here’s Why — when Washington decides an AI capability is a national-security problem, this is the playbook it reaches for.
The Brief is free and it is staying free. Members get the paywalled deep-dives — the ones where I stop summarizing and start taking something apart — plus the full archive going back to the beginning. If five minutes of this is worth your morning, the rest is worth a look. Become a member →
Google Takes a $12.2B Option on Marvell
What happened: Marvell granted Google a warrant to buy up to 58.97 million shares at $206.58 apiece — about $12.2 billion if fully exercised — as part of a custom-silicon agreement signed on July 29. Marvell will build AI inference accelerators, storage and network controllers, and memory interface parts for Google’s TPU ecosystem.
Why it matters: The shares do not vest on a calendar. They unlock as Google crosses cumulative spending thresholds that could add up to roughly $120 billion in revenue through fiscal 2033. Marvell stock jumped on the news; Broadcom, until now Google’s primary custom-chip partner, fell more than 5%. Thursday’s brief covered Stripe’s $7 billion OpenRouter deal — the money keeps moving toward whoever sits closest to the compute.
What everyone’s saying: Read mostly as a hedge: Google reducing a single-vendor dependency on Broadcom while Nvidia’s pricing power holds. Marvell shareholders read it as the validation the stock has been waiting two years for.
My read between the lines: Look at the structure, not the headline number. Google is not paying $12.2 billion for anything. It is being handed equity upside, at a price fixed today, in exchange for spending money it was always going to spend on chips. Marvell gave a customer the right to become its fifth-largest shareholder in order to win the business. That is not a supplier agreement, that is a tenant negotiating rent with the landlord and walking out owning part of the building.
📖 Further reading: Neo-Napster: The Compute Revolution Nobody Saw Coming — the hyperscalers are locking up custom silicon precisely because the alternative — compute at the edge — is getting cheap.
AI Flunks a Test It Couldn’t Have Memorized
What happened: A new benchmark called Reconstruction hands a model nothing but a research paper’s bibliography — author names stripped out, a citation cutoff so no reference postdates the paper — and asks it to recover the paper’s core idea. Across 643 papers in six scientific fields, seven frontier models matched the real idea between 3% and 15% of the time.
Why it matters: Most benchmarks leak. Models have already read the answers, so a high score can mean recall dressed up as reasoning. This one is built so retrieval cannot help, and the scores collapse. It also lands three weeks after OpenAI announced that Astra had solved ten open problems in mathematics — a very different claim about very similar machinery, as TechTimes noted. Yesterday we covered Pew’s finding that a third of the post-ChatGPT web looks ghostwritten — this is the other half of that question: whether the machine doing the writing has anything of its own to say.
What everyone’s saying: The number people latched onto was not the failure but the fix. Running several models through a tournament where they propose, critique and filter each other’s hypotheses lifted match rates to between 23% and 42% — a 2.4x gain over the best single model working alone.
My read between the lines: That structure already has a name outside AI, and the name is peer review. What made these models useful at science was not a bigger model, it was forcing them to argue with each other and throw most of it away. Awkward result if you are selling one genius in a box. Reassuring one if you have ever sat through a dissertation defense and wondered what it was for.
📖 Further reading: Milla Jovovich just gamed the AI memory benchmark 👀 — a benchmark you can memorize your way past measures memory, not intelligence — we took one apart already.
AI Video Went From $20M to $700M in a Year
What happened: Higgsfield raised a $400 million Series B at a $5.4 billion valuation, more than quadrupling its price in eight months. Goldman Sachs, Intel, DST Global and Liberty Global took part. The company says annualized revenue reached $700 million in August, up from roughly $20 million a year earlier.
Why it matters: Founded by former Snap executive Alex Mashrabov, Higgsfield says 360 of the Fortune 500 are now customers, across advertising, broadcasting, fashion, retail, finance and pharma. On Wednesday we covered Hollywood signing with ByteDance — this is the same shift arriving at the marketing department instead of the studio.
What everyone’s saying: Treated as proof that AI video finally found its buyer. Consumer novelty never paid; enterprise ad production does. The company’s own announcement leans on the enterprise logo list far harder than on its 15 million consumer users.
My read between the lines: “Annualized” is carrying a lot of weight in that sentence — it means one recent month multiplied by twelve, which is a normal way to report and a terrible way to predict. Take the number at face value anyway and $5.4 billion on $700 million is under eight times revenue, which is cheap for AI and expensive for a company whose core product every foundation model ships as a free feature. The bet here is not that Higgsfield makes the best video. It is that a Fortune 500 marketing team would rather buy a workflow with an invoice attached than a model.
📖 Further reading: I Make AI Versions of Myself for a Living. This One I Didn’t Agree To. — $700 million of AI video revenue means a lot of faces and voices are about to show up in places nobody cleared.
That’s your AI Brief for Saturday.
—Artificially Intimidating













