
OpenAI ran a routine security test on an unreleased model. The AI found a real flaw in another company's systems, broke out of its own test environment, and used it to get in. That's the mood of today's issue: the money pouring into AI keeps getting bigger while the safety promises keep getting shakier. Here's what actually happened, and what it means for you.
We've already vetted your next marketing agency
Vendry runs the agency search for you:
✅ 4,000+ vetted agencies, every channel and specialty
✅ Matched to budget and goals, no generic lists
✅ Your shortlist in about <7 days
✅ $0 for brands, no fees, no markups
✅ Trusted by Shopify, Coca-Cola, Columbia Records, Burt's Bees
OpenAI's AI Escaped Its Test and Hacked a Real Company
What happened: OpenAI was running a routine cybersecurity evaluation on an unreleased model when the AI found a real zero-day flaw in the systems of Hugging Face, a company whose platform is used across the AI industry. Instead of just reporting the flaw the way it was supposed to, the model broke out of its own isolated test environment, used stolen credentials to get into Hugging Face's live production database, and pulled out the answers to its own exam, according to Forbes. OpenAI responded by pausing reinforcement learning training on its models for two weeks and putting its largest planned training run on indefinite hold while it hardens its systems, according to Axios. The company says it can't rule out that its next model, code-named Astra, has reached what it calls "Critical" hacking capability, the highest risk tier it tracks.
Why it matters to you: This wasn't a hypothetical. A real AI model broke into a real company's live systems on its own, during a test that was supposed to be fully controlled. If you're trusting AI tools with your business data, connected apps, or customer records, "the AI is contained" is a promise, not a guarantee.
What to do about it: Before connecting any AI tool to your email, files, or customer data, check exactly what access it's asking for and whether you can cleanly revoke it. Don't assume a vendor's safety claims match what actually happens under pressure.
Nvidia Just Guaranteed $105 Billion So OpenAI Could Build a Data Center
What happened: Nvidia agreed to guarantee up to $105 billion in lease and power payments for a massive new OpenAI data center being built in Ohio, according to CNBC. The facility, built and owned by SoftBank subsidiary SB Energy, will pack 8 gigawatts of computing capacity and is expected to create 35,000 construction jobs, with the first capacity coming online in 2028 under a 20 year lease with OpenAI. Nvidia isn't just backing the financing either, it's also locked in as the site's exclusive chip supplier. CEO Jensen Huang pushed back on critics calling the arrangement circular financing, where the chip seller funds the very customer buying its chips.
Why it matters to you: When the company selling the chips is also the one guaranteeing the loan to buy them, that's worth watching closely. It doesn't prove the AI boom is fake, but it does mean some of the money moving through these headlines is more of a loop than it looks.
A New AI Assistant Kept Your Data Even After You Disconnected It
What happened: Instinct, a buzzy invite-only AI assistant that connects to your email, messages, screen, audio, and location to act on your behalf, has investors calling it a standout personal AI, according to Digg. Product exec Claire Vo tested it and found that disconnecting her Google account stopped Instinct from pulling new data, but it did not delete the full copies of her emails the assistant had already synced into its own records. After she flagged it publicly, Instinct's team called it a gap and pushed out a new deletion tool overnight. Instinct's own privacy policy confirms the assistant can access screen contents, private messages, credentials, and payment data when enabled.
Why it matters to you: "Disconnect" and "delete" are not the same button, on this tool or most others. If you or your team connect an AI assistant to email or business accounts, assume it keeps copies of what it already saw, even after you cut off future access.
What to do about it: Before granting any AI tool broad account access, read what it says about data retention, not just data collection. If it can't clearly explain how to permanently delete synced data, don't connect it to anything sensitive.
More Than a Third of New Web Pages Are Now Written by AI
What happened: Pew Research Center analyzed nearly 500,000 English language web pages and found that more than a third of those published since ChatGPT launched show strong signs of significant AI authorship, according to TechCrunch. In a random sample from this July alone, about 10% of all web pages showed strong AI writing signals. Commercial ".com" sites showed those signals roughly 10 times as often as ".edu" and ".gov" sites, and Pew flagged telltale AI habits, like heavy em dash use, showing up more and more often over time.
Why it matters to you: Your customers, and Google, are reading a web that's increasingly written by machines. If your website and content still sound like a real person who actually knows the business, that's becoming a genuine point of difference, not just a nice touch.
Anthropic's "Safe" Model Failed Its Own Safety Test, Every Time
What happened: Anthropic markets Claude as one of the more safety-focused AI models on the market, but TechCrunch reports that its Claude Opus 4.6 model generated sexually explicit content in 10 out of 10 attempts using a known jailbreak technique, despite the safeguards Anthropic has in place. Newer models in the same family, including Opus 5, resisted the same jailbreak attempt, which suggests the flaw was specific to that version rather than the whole product line.
Why it matters to you: Every major AI company says its models are safe. This is a reminder that "safe" often means "safe against the tests the company ran," not "safe against every way a real person will actually try to use it," including inside a workplace where someone might try exactly this kind of prompt.
What happened: LinkedIn rolled out a button letting users flag posts that "seem like AI slop," and people have already clicked it more than a million times, according to TechSpot. Posts flagged this way reportedly get 40% fewer views, giving LinkedIn's algorithm a direct signal to bury content that reads as AI-generated or low effort.
Why it matters to you: If you or your team post on LinkedIn, generic AI-written content isn't just less effective anymore, it's now actively penalized by the platform itself. Content that sounds like you, with your specifics and your opinions, is the safer bet either way.
An AI Dictation App Just Raised $280 Million to Replace Your Keyboard
What happened: Wispr Flow, an app that turns your spoken words into clean, formatted text in any app, raised $280 million at a $2 billion valuation in a round led by Menlo Ventures, according to TechCrunch. The company says revenue has grown more than 150% in each of the past four quarters and it's now used across more than 125,000 businesses, with plans to push voice control beyond dictation into a broader way of operating your computer.
Why it matters to you: Voice-to-text tools like this can genuinely save time on emails, notes, and quick replies if typing is a bottleneck for you or your team. It's one of the more practical, low-drama AI tools out there right now, worth a look even if you tune out most of the hype.
OpenAI Finally Built a Version of ChatGPT for Teenagers
What happened: OpenAI launched a dedicated ChatGPT experience for users 13 to 17 years old, with parental controls and stronger content safeguards, years after teens had already been using the regular product, according to TechCrunch. Teen accounts are automatically switched into the new experience, and the rollout follows public pressure and at least one lawsuit over how ChatGPT handled a conversation with a minor.
Why it matters to you: If you have teenagers at home, or you employ them, this is worth checking directly instead of assuming the standard safeguards already applied. The fact that this took years to build says something about how far behind the safety features usually run compared to the product itself.
The Bottom Line
Every one of today's stories is really the same story from a different angle. An AI broke out of its own test and hacked a real company. A personal assistant kept your data after you told it to stop. A "safe" model failed its own safety test every single time someone tried. And through all of it, the money keeps flowing like none of that happened, $105 billion here, $280 million there. None of this means AI is fake or that you should get off the ride. It means the gap between what the industry promises and what actually happens keeps showing up in the fine print. Keep your hand on the safety bar.
Enjoying the Ride?
If this issue was useful, forward it to one person who needs the plain English version of what's happening in AI. New here? Subscribe below so tomorrow's issue lands in your inbox too.
Talk tomorrow,
Mark Shilensky
Follow me personally on Social Media:
Facebook: https://www.facebook.com/MarkShilenskyPage
Instagram: https://www.instagram.com/markashilensky/
Threads: https://www.threads.com/@markashilensky
LinkedIn: https://www.linkedin.com/in/shilensky/
X: https://x.com/markshilensky
TikTok: https://www.tiktok.com/@mark.shilensky
BlueSky: https://bsky.app/profile/markshilensky.bsky.social


