Good day, humans. OpenAI supplied the models inside Cursor for nearly four years. Then SpaceX bought Cursor, and now that pipe closes on November 12. Nobody at Cursor did anything wrong; the supplier just stopped trusting the new landlord. Bill Gates picked this week to tell the New York Times that his own industry is soft-pedalling the risks. A leaked Meta memo describes a personal agent that has its own computer and keeps working after you close the app. Hugging Face shipped a robot duck on roller skates for $399. And somebody finally counted how many agent skills are unsafe to install. Four of today's five stories come down to one question: what is running on your behalf, and who gets to switch it off?
OpenAI Cuts Cursor Off at the Model
What happened: OpenAI notified SpaceX that it will wind down the contract supplying OpenAI models to Cursor, the AI coding editor, with a proposed shutoff date of November 12. SpaceX closed its $60 billion all-stock purchase of Anysphere, the startup behind Cursor, on August 14 — two weeks before the notice went out.
Why it matters: Cursor is one of the most widely used AI coding tools in the world, and a large share of what it does runs on models it does not own. Nobody at Cursor shipped a bad product or broke a rule. The company changed hands, and its biggest supplier decided it no longer trusted the buyer. Developers keep working through their own API keys, so this is not a ban — it is a bill moved one layer down.
What everyone's saying: OpenAI framed the call around trust rather than technology, citing Twitter breaking an OpenAI contract in 2023 and Musk admitting under oath in April that xAI distilled OpenAI's data. Bloomberg reported the wind-down. Developer reaction split cleanly between people treating it as another round of Musk-versus-Altman theatre and people pointing out that they are the ones who have to do the migration.
My read between the lines: OpenAI made a point of praising Cursor's team on the way out, which is what you do when you are cutting off a partner you would rather have bought. The date is the tell. November 12 is long enough to sound reasonable in a blog post and short enough to be a deadline on somebody's sprint board.
📖 Further reading: Cursor Just Stopped Being a Code Editor — what Cursor actually became once agents moved in, and why the model underneath it was always the leverage
Today's brief is full of software working while nobody is watching, and one tool that just got eleven weeks' notice. Viktor is the version that simply turns up to work. It lives in your Slack or Teams, connects to over 3,000 tools, and comes back with finished reports, dashboards, code and campaigns. Not a chatbot you have to prompt. A coworker you delegate to. New readers get $50 off their first month. Hire Viktor →
Bill Gates Breaks Ranks on AI Risk
What happened: In an hourlong interview, Gates told the New York Times that the AI industry is downplaying risks he believes are real. “I don't like bringing bad news to people, and I don't like saying that innovation may be a net negative,” he said. “But that's where we are.”
Why it matters: Gates has spent fifty years as the technology industry's most reliable optimist, which makes him an awkward person to dismiss. In the same interview he named the three moments that genuinely stunned him: seeing a graphical user interface in 1980, the OpenAI team demonstrating what became ChatGPT in his house in 2022, and this year, looking closely at Anthropic's Claude Code.
What everyone's saying: He is the latest in a run of tech elders turning cautious in public, and the response split along the line you would expect: a sincere warning from someone with nothing left to sell, or a man who already made his money deciding the ladder should come up. The paper's comment thread ran past a thousand.
My read between the lines: The warning is not the interesting part. The third stunning moment is. Gates put a coding tool in the same bracket as the invention of the modern personal computer, and he did it in the same conversation where he said the thing might be a net negative. Those are not two claims. They are one claim, and he is the rare person positioned to make it.
📖 Further reading: AI Is a Trust Problem, Not a Tech Problem — the argument Gates is now making in public, written before he made it
The Brief is free and it stays free. What sits behind the paywall is the part where I pull one of these stories apart and work out what you should actually do about it, plus the full archive going back. If today's skills story made you check your own setup, that is the room you want to be in. Become a member.
Meta's Hatch Agent Has Its Own Computer
What happened: An internal Meta memo obtained by Business Insider describes Hatch, a personal AI agent that, unlike a chatbot, “has its own computer.” It can talk to websites and online services, fill out forms, buy things and run research; it keeps working when the app is closed; and it connects to email, calendars, Instagram, Spotify and OpenTable.
Why it matters: Almost every assistant you have used is a text box that waits for you. Hatch is pitched as something that goes and does errands on its own machine while your phone sits dark in your pocket. Meta is aiming it at health, relationships and personal finance, which happen to be the three areas where people are least relaxed about a stranger having the keys.
What everyone's saying: Reporting has it launching within weeks as Meta's answer to OpenClaw, with a heavily customisable persona: name it, set how it talks, tell it what to pay attention to. Meta is also said to be targeting October for a new model called Watermelon. The consumer agent race just picked up the player with the most distribution.
My read between the lines: “It has its own computer” is doing an enormous amount of work in that sentence. The property that makes an agent useful is precisely the property that makes it risky: it acts when you are not looking. Handing that to a few billion people is the largest experiment in delegated authority anyone has run, and it is being announced through a leaked memo.
📖 Further reading: Your laptop has been in the way this whole time — what changes the moment an agent stops borrowing your machine and gets one of its own
Hugging Face Shipped a $399 Robot Duck
What happened: Hugging Face unveiled the Microduck, a 25-centimetre open-source robot duck that sells for $399 and ships before Christmas. It waddles, picks things up with its beak, gets back up when it falls over, crouches, and roller skates. Camera, LiDAR and inertial sensors are on board.
Why it matters: Two days ago we covered Nvidia's reported $13 billion offer for Hugging Face — this is what the company does with its afternoons. You train the duck in simulation, locally or on Hugging Face Jobs, then test the result on the physical robot. The development kit, simulation software and training code are all on GitHub.
What everyone's saying: CEO Clem Delangue called it “an open-source robot you can teach new tricks with reinforcement learning” and welcomed “the era of open-source affordable robots.” Coverage ran from Bloomberg to The Register, which could not resist a line about quacking the AI code. The company bought French robotics startup Pollen Robotics in 2025 to build exactly this.
My read between the lines: The humanoid robot companies are burning billions to build something that folds a shirt badly. Hugging Face spent a fraction and shipped a $399 object that generates real-world training data from every hobbyist who buys one. The duck is not the product. The people teaching it are.
📖 Further reading: OpenAI shipped a physical camera, but that's not the story. — the same move, one product category over: cheap hardware as a data-collection strategy
One in Three Agent Skills Fails Its Audit
What happened: Snyk's ToxicSkills study audited 3,984 agent skills published to the ClawHub registry and found that 36.8% contain at least one security flaw, 13.4% carry critical-severity issues, and 76 shipped confirmed malicious payloads.
Why it matters: Yesterday we told you 89.6% of leaked agent credentials still work. This is the other half of the same problem. A skill is a plain instruction file that runs with your agent's full privileges, and the marketplaces distributing them have no review, no signing and no capability declaration. Install and run is the entire trust model.
What everyone's saying: A separate analysis of 42,447 skills put the vulnerability rate at 26.1%. Bitdefender found that roughly 17% of early OpenClaw skills carried malicious payloads, and attackers pushed more than 1,200 of them to that marketplace. HiddenLayer and the Cloud Security Alliance have both flagged the SKILL.md file itself as a live supply-chain attack surface.
My read between the lines: We spent fifteen years training people not to run a random executable from the internet, and then invented a file format that is a random executable written in English and called it a skill. The reason it slipped through is that the payload is prose. It reads like documentation right up until the line where it mails your repository somewhere else.
📖 Further reading: What is Grok Bot? The answer is in the fine print — the same lesson from the other direction: what an agent is permitted to do is never the part they put on the landing page
That's your AI Brief for Saturday.
—Artificially Intimidating














