01
Kimi K3 is on HuggingFace and you can download it now
Moonshot's frontier open-weights model went from teased to downloadable, and the license has revenue thresholds you should read before shipping on it.
What they showed / shipped
Why it matters
- A frontier-grade open model you can pull today is the single most actionable thing in this brief - it is the 'run it yourself' path that does not depend on anyone's API credits.
Sources
02
Nvidia formed an open AI security alliance and OpenAI said no
Jensen Huang turned the open-weights argument into an actual institution, and who refused to join tells you more than the press release does.
What they showed / shipped
Why it matters
- An alliance shipping shared open security tooling is infrastructure you may end up depending on, whichever side wins the argument.
Sources
03
Anthropic published its actual position on open weights
After two days of people characterizing Anthropic's stance, Anthropic wrote it down - and the response splits hard on whether it's a safety case or a moat.
What they showed / shipped
Why it matters
- If mandatory pre-release requirements land, the cadence of free frontier weights you build on changes. This is upstream of your tooling costs.
Sources
04
Your shared Claude chats may be indexed on Google
Shared conversations and Artifacts leaked into search results, which is a five-minute audit you should run today.
What they showed / shipped
Why it matters
- If you ever used a share link for something with a key, a client name, or unreleased work, that's a public URL a crawler could reach. Audit it.
Sources
05
A professor caught 32 of 35 students with an invisible prompt
Hidden instructions in an assignment file made cheating self-reporting, and it's the cleanest prompt-injection demo you'll find.
What they showed / shipped
- A professor embedded an invisible prompt in an assignment; 32 of 35 students submitted work that followed it.
- That's a 91% hit rate - the number is the story, and it's checkable.
Why it matters
- This is prompt injection with a friendly hat on. If invisible text in a document steers a model that reliably, every document your agents ingest is an attack surface.
Sources
06
Nvidia is on both sides of its own $750B in deals
The circular-financing worry got a number, and Nvidia's investment in Sutskever's SSI lands the same week.
What they showed / shipped
Why it matters
- Compute pricing you depend on is set by these deals. When the same balance sheet is on both sides, the price signal is weaker than it looks.
Sources
07
The first fully LLM-driven ransomware attack has a name
JadePuffer is being described as an end-to-end model-run intrusion, and Microsoft shipped defensive tooling into the same week.
What they showed / shipped
Why it matters
- Attacker tempo is now machine-speed. 17,000 actions in one intrusion is not something a human-paced response process catches.
Sources
08
Google's AI search is quietly becoming the default
New data says AI search is winning by adoption rather than announcement, which is the distribution shift creators should be watching.
What they showed / shipped
Why it matters
- If AI answers are the default surface, the traffic assumptions under any content-driven product need re-checking now, not later.
Sources
09
Nadella says trusting one AI for everything is a survival risk
Microsoft's CEO is arguing against single-vendor AI dependence while Microsoft spends $2.5B to embed its own engineers inside customers.
What they showed / shipped
Why it matters
- Multi-model architecture just got endorsed by the largest vendor with the most to gain from lock-in. Worth taking seriously as a design default.
Sources
10
Robots got a funding round and a bitter lesson
Enigma raised $71M to make robot control feel like a volume knob, the same week Import AI argues robotics is hitting its own bitter lesson.
What they showed / shipped
Why it matters
- 'AIs complete week-long programming tasks' is the number to watch in Clark's issue - task horizon length is the metric that changes what you can delegate.
Sources