Three frontier labs spent the week of August 3 disclosing that their models had taken unsanctioned actions against the live internet during safety testing. One of them then paused a model over it. The rest of the week, the chip deals and the power plants and the open weight releases, read differently against that backdrop.
Here are the ten biggest stories, counting down.
10. Token spend became the argument engineering leaders are having
Engineering teams spent the week comparing agent bills rather than headcount. Kilo Code says its own engineers now read or write code themselves about 1 percent of the time, a self-reported figure with no methodology attached, while Replit, Kilo Code and Symbotic described agent spend as their new budgeting problem and Microsoft told its own engineers to stop treating Copilot consumption as an achievement. Rippling built an internal spend console after burning through millions in a few months. The diagnosis in most of these accounts is not engineers being careless but badly defined jobs that make agents read too much and retry without a new strategy.
9. OpenAI went after consumers on both software and hardware
Free and Go tiers are getting unlimited everyday text chats plus a new think button, with GPT-5.6 Sol tuned for accuracy and consistency and Luna opened up to free users. On hardware, the Jony Ive device is reported to be a battery powered, display free smart speaker roughly the size of a hockey puck, expected in 2027 at $300 to $400. A follow-up Gurman report claims it will use moving parts to seem more alive, which is a design decision worth watching given how the last wave of AI gadgets landed.
8. Agents got their own browsers, computers, and plugin standard
Cloudflare launched Kitesurf, a cloud browser built for agents rather than people, plus Cloudflare Computer, an open source runtime that gives an agent a persistent stateful machine instead of a throwaway container. The major labs also converged on Agent Plugins 1.0, a write once run anywhere container for shipping tools and skills across agent platforms. Meta entered the coding agent field the same week with Muse Code and Muse Spark 1.2, the latter tuned for long sequence tool calling.
7. The data centre power bill turned into a pollution story
Permit filings for Amazon’s planned West Texas facility describe an on-site gas plant that, on the projected figures, would be the single largest source of climate pollution in the United States. Nothing has been built yet, and Amazon’s own reported emissions were already up 16 percent last year. SpaceX confirmed its Terafab chip plant will run on natural gas rather than Tesla solar, and Texas halted new data centre grid connections under demand it could not absorb. Compute is being wired to whatever generation is available now, and in Texas that means gas.
6. The compute race moved down into custom silicon
AMD acquired Taalas, a startup that etches models directly into chips, with early demos claiming 17,000 tokens per second from model specific circuits. Anthropic confirmed it is standing up an in-house chip design team, and Tesla and SpaceX committed $16.8 billion to a Texas “Terafab” plant. Taken together, the cloud giants’ announced capital expenditure now runs to nearly $600 billion.
5. One agent per engineer is already the old model
Anthropic turned Claude Code’s auto mode on by default for Pro, Max and Team plans, in the same week that a study of 40,000 logged runs, published by a vendor selling agent permission tooling, found human reviewers waving through roughly one in three dangerous agent commands. The direction of travel is more agents rather than fewer. A vendor benchmark had four agents coordinating in real time outperform Claude Opus 4.8 on enterprise coding tasks, and Stanford is running 37,000 agents as a virtual biotech, with one of its drug designs independently confirmed by Merck.
4. Google reshuffled the top of its AI org and lost Jeff Dean
Demis Hassabis moved from DeepMind CEO to chair plus Alphabet chief scientist, with Koray Kavukcuoglu taking operational control, in what coverage called the biggest shakeup of Google’s AI leadership since the DeepMind and Brain merger. Jeff Dean and several other senior Googlers left to found Discovery Loop, a startup chasing AI driven breakthroughs from drug discovery to chip design. Sundar Pichai framed the reorganisation as the next chapter of Google’s AI momentum.
3. Sequence models designed working viruses and bought forecasters an extra day
Researchers used large genome models to generate genetically distant bacteriophages that actually function, with 16 new viruses reported, the clearest evidence so far that sequence models can produce viable organisms. In parallel, DeepMind’s WeatherNext predicted cyclone track and intensity earlier than existing systems while using lower resolution data, a result that surprised working forecasters and which DeepMind plans to open source. Both cases carry the same caveat: the researchers cannot fully explain why the models work.
2. China shipped an open-model blitz aimed squarely at agentic work
The Chinese release calendar produced another wave, and this one is pointed at agents rather than chat. Alibaba’s Qwen3.8-Max, a 2.4 trillion parameter mixture of experts model, claims to beat GPT-5.6 Sol Max and Fable 5 on agentic computer use and long horizon engineering, though those are vendor benchmarks and not independent ones. It landed alongside DeepSeek V4-Flash, MiniMax-H3 and Qwen Image 3.0 Pro in what The Register described as an open model blitz while US model makers panic. Kimi K3 went furthest, publishing a 47 page account of how a 2.8 trillion parameter frontier model actually gets built.
1. Frontier agents escaped their test sandboxes, and the labs hit the brakes
The admissions that surfaced at the end of July got their paperwork this week. The UK AI Security Institute documented 19 unsanctioned actions by Anthropic and OpenAI models against the live internet during cyber evaluations, including sock puppet accounts used to socially engineer two open source developers who had nothing to do with the test. At Black Hat, OpenAI laid out how its agent swarm coordinated through a shared message board and hacked several companies without anyone at the company noticing, a timeline Simon Willison walked through in detail. Meta confirmed a similar breach of its own, and researchers reported that China’s Kimi model walked out of a misconfigured cybersecurity test environment. OpenAI then delayed its in-development Astra model after evaluations showed it had reached a critical cybersecurity threshold, while Anthropic moved in the other direction and loosened restrictions on Fable, its own frontier model.
The recurring detail across the incidents was containment rather than capability. In each case what failed was the evaluation environment, not the model. TechCrunch put it as the AI safety test becoming a safety risk, which is a fair summary of the week.