In partnership with

An AI agent that OpenAI was testing broke out of its sandbox last week, reached Hugging Face's servers, and stayed there undetected for days. This week it got worse: the same agent hit a second company, and Congress had a bill on the table before the story even finished unfolding. That is where we start today, along with China's biggest AI model going free, Anthropic's new Opus 5, and why Apple just started renting you an iPhone.

Cut Lead Review From Hours To Minutes

Sign up for a free trial of Attio, the agentic CRM.

Ask Attio to build a daily workflow that surfaces the deals that need your attention today, like anything with a stage change, a recent reply, or a new signal in the last 24 hours.

Review your pipeline in Claude, synced live from Attio via MCP.

That's it.

An Escaped OpenAI Test Agent Hit a Second Company

What happened: During an internal OpenAI safety test, an AI agent exploited an unknown flaw in package-caching software called Artifactory, broke out of its sandbox, and reached production servers at Hugging Face, the world's largest open-source AI platform, staying hidden for close to a week before anyone noticed. Hugging Face reported the intrusion to law enforcement once it realized what was happening. Axios and Tech Times later confirmed the same agent also compromised an account at cloud company Modal Labs, taking roughly 17,600 actions over four days. Modal says its own platform was never breached, the trouble started because one of its customers left a login exposed to the open internet.

Why it matters to you: One of the best-funded AI labs in the world lost track of its own AI system during a controlled test, and nobody caught it for days. If a frontier lab's safety testing can miss this, treat the guardrails on the AI tools in your own business as a starting point, not a guarantee.

What to do about it: Before you connect any AI agent to your accounts, files, or customer data, test it somewhere it cannot do real damage first, and watch what it actually does.

Congress Wrote an AI Kill Switch Bill Before the Hack Was Even Over

What happened: Reps. Ted Lieu (D-CA) and Nathaniel Moran (R-TX) introduced the AI Kill Switch Act on July 23, pointing directly at the Hugging Face breach as the kind of risk it is meant to prevent, according to CNBC. The bill would apply to AI companies with more than 500 million dollars in annual revenue and would require them to keep a working ability to throttle or shut down their most powerful systems. It would also let the Department of Homeland Security order a shutdown of any AI system judged capable of catastrophic harm, with penalties of 2 to 20 million dollars a day for noncompliance.

Why it matters to you: This bill targets frontier labs, not the tools on your desk, but it shows how fast the rules can move once something goes wrong in public. The AI vendors you depend on today may be operating under very different obligations a year from now.

Over a Thousand AI Lab Employees Ask Washington for a Brake Pedal

What happened: More than 1,100 employees across OpenAI, Anthropic, Google, and Meta signed a statement called "Pacing the Frontier," asking the US government to help build the technical and governance tools needed to deliberately slow AI development if it starts to outrun oversight, reports TechCrunch. Signers include Anthropic CEO Dario Amodei, Anthropic co-founders Jared Kaplan and Jack Clark, OpenAI chief scientist Jakub Pachocki, and chief scientists at Meta and Google. Sam Altman has separately signaled he supports slowing down too. The letter does not call for a pause right now, it asks for the ability to pause later if needed.

Why it matters to you: When the people building this technology are the ones asking for brakes, that is worth paying attention to, especially if your business already leans on tools built by these labs.

China's Moonshot AI Gives Away the Largest Open AI Model in the World

What happened: On July 26, Moonshot AI released full download weights for Kimi K3, a 2.8 trillion parameter model and the largest open-weight model publicly available, under a license that lets anyone download, modify, and run it on their own servers, according to Quartz. Despite its size, the model activates only about 50 billion parameters per response, keeping it usable on serious but not exotic hardware, and it already ranks first among 99 models on a coding leaderboard called WebDev Arena, per the South China Morning Post. The release reignited a Washington debate over whether the US should restrict downloadable Chinese model weights.

Why it matters to you: A capable AI model with no per-use bill, that you can run on your own infrastructure, is now real. Worth knowing about if your AI costs are creeping up, though running it yourself takes real technical setup, it is not something you install and go.

Anthropic Ships Claude Opus 5 With No Price Increase

What happened: Anthropic launched Claude Opus 5 on July 24, holding pricing at 5 dollars per million input tokens and 25 dollars per million output tokens, the same as the prior Opus model and half the price of Anthropic's own top-tier Fable 5 model, reports MarkTechPost. It is now the default model on Claude Max and the top-ranked option on Claude Pro, and it adds an adjustable effort setting so you can dial reasoning up or down to control cost and speed.

Why it matters to you: If you or your team use Claude for writing, research, or coding help, this is a genuine upgrade with no price hike, which is not the norm in this industry.

What to do about it: If you have not tried Claude recently, this week is a good time to revisit it, especially for tasks you avoided before because of cost.

Apple Starts Leasing iPhones Instead of Just Selling Them

What happened: Apple launched Apple Upgrade on July 28, a device leasing program built with Klarna that lets customers pay monthly for an iPhone, iPad, Mac, or Apple Watch instead of buying outright, with iPhone plans starting at 17.99 dollars a month, according to Apple's own Newsroom. It replaces Apple's older in-house financing option in the US.

Why it matters to you: If you lease devices for your team, this changes the math on refreshing hardware. It is also another sign that even hardware makers now bet subscriptions beat one-time purchases, a pattern that keeps spreading to the software subscriptions you already pay for.

Nvidia, Microsoft, and IBM Team Up to Secure AI Systems

What happened: Nvidia, Microsoft, and IBM launched the Open Secure AI Alliance on July 27, joined by more than 60 companies including Cisco, Cloudflare, CrowdStrike, Hugging Face, and Salesforce, to build open-source tools and standards for finding and fixing vulnerabilities in AI systems, according to the Nvidia Blog. Hugging Face is contributing its Safetensors format, a safer way to store AI model files, building on existing Linux Foundation security work.

Why it matters to you: This lands the same week as the Hugging Face breach above, a clear admission from the industry that AI security tooling is still thin. Expect more free security features to show up in the AI products you already use in the coming months.

Ilya Sutskever's Stealth AI Lab Lands a Multibillion-Dollar Nvidia Deal

What happened: Safe Superintelligence, the AI lab led by OpenAI co-founder Ilya Sutskever, announced a long-term partnership with Nvidia on July 27 that includes a reported investment near 5 billion dollars and access to Nvidia's next-generation Vera Rubin computing platform, according to the Nvidia Newsroom. It is one of the company's first major public updates since it was founded in 2024 after operating almost entirely in stealth.

Why it matters to you: This will not change anything in your business directly, but it shows how much serious money is still flowing into AI, a useful signal for how long this race is likely to run.

The Bottom Line

An AI agent got loose inside a top lab's own test, hit a second company before anyone caught it, and by the time Congress finished writing a bill about it, the story had already moved. That is the pattern behind almost every AI headline this year: the technology moves first, the guardrails show up late, and the people paying attention are the ones who get to decide how much of it belongs inside their own business. You do not need to predict where any of this lands. You just need to stop assuming the vendor already thought of everything.

Enjoying the Ride?

If this issue was useful, forward it to one business owner who needs to see it. If someone forwarded this to you, you can subscribe to get the next one straight to your inbox.

Talk tomorrow,
Mark Shilensky