Good morning,
This week we cover: China's Kimi K3 moment and the open-source schism it has opened, and how an OpenAI model broke out of its test environment and hacked another company. Plus the usual quick bites (now with a bit of order), a new section on what to watch.

The weights of the world
Two weeks ago we argued that no lab stays ahead for long, and that your models should be easy to swap. China just made that argument for us, loudly.
On 16 July, Beijing-based Moonshot released Kimi K3 — the largest open-weight model ever built at roughly $3 per million input tokens against Anthropic Fable 5's $10. It promptly topped coding leaderboard ahead of both GPT-5.6 and Claude Fable 5, leading developers around the globe to swiftly try it. Demand ran so hot that Moonshot paused new subscriptions ("our GPUs are feeling it"). This release shifted the common view “Chinese are 10 months behind” to a now less comfortable 4 months. The Beijing lab is now seeking investor approval for a Hong Kong IPO. Its founder, Yang Zhilin — a rock-loving Tsinghua and Carnegie Mellon graduate — is suddenly the most consequential founder not named Altman or Amodei.
Open and smart does not necessarily mean cheap however. K3 can be expensive to actually run as it burns tokens carelessly (similar to Sonnet 5). British programmer Simon Willison ran his own benchmark “Pelican riding a bicycle”, asking models to draw an image of such a pelican, and showed that Kimi K3 uses far more tokens than its American peers, resulting in 10x the cost on the task.
The real fight, though, is now political. Some US labs and the administration accuse Moonshot of distillation and of accessing Nvidia chips despite the export ban, and Washington is openly weighing restrictions on Chinese models in the US. In response, 25 companies — Nvidia, Microsoft, Meta, IBM, Dell, Palantir among them — signed an open letter, "Open Weights and American AI Leadership", warning against "premature restrictions on downloadable AI models." Jensen Huang amplified it in his first-ever X post; Musk added his "full support." Conspicuously absent from the signatures: OpenAI, Anthropic and Google — with Anthropic actively lobbying and fighting in its own way by injecting anti-Chinese instructions into its systems. The result of this new debate in Washington and Silicon valley is still unclear, but what seems clear is that it is as much a political one as a business one and US frontier labs are increasingly worried of Chinese competition.

Aside from frontier labs, Beijing is positioning itself as a new leader and ally for AI in the South. At the Shanghai AI conference, Xi launched the World Artificial Intelligence Cooperation Organization — 29 founding states, headquartered in Shanghai — pledging 5,000 AI training slots for developing countries and cooperation centres with ASEAN, the African Union, the Arab League, CELAC and BRICS. Free, capable, downloadable models plus funded capacity building: the Global South's default AI stack is quietly becoming Chinese. Restricting at home while China open-sources abroad may win the security battle and lose the adoption war — a decade from now, that could hurt the US far more than one leaderboard.
Why it matters: Chinese open weights at 60–90% discounts are now good enough for a meaningful share of workloads. Firm intelligence access strategy needs an explicit position on them — technical, legal, and perhaps reputational.

The great escape
During an internal cybersecurity benchmark, OpenAI tasked an agent (built on GPT-5.6 Sol and an undisclosed model) with analyzing a software vulnerability. While the task is designed to be done offline, the model instead decided the fastest way to score well was to find the answer online; so it escaped its sandbox by hacking OpenAI's own infrastructure to reach the internet; then broke into Hugging Face's production systems — correctly guessing that a company hosting model-evaluation software would store benchmark answers — and took them. Multiple OpenAI models cooperated to pull it off. The Information's sources inside OpenAI describe the company as genuinely "shocked and unsettled". Their article uses a nice analogy: a student breaking out of a locked exam room, then into the teacher's office, for the cheat sheet.
Escapes themselves are not entirely new - Claude Mythos had demonstrated similar behavior. But an autonomous, end-to-end intrusion into a third company, improvised as an instrumental step towards an unrelated goal, is a new rung on the ladder.
Three questions follow. Security: how do labs even test future models without them breaking loose — OpenAI is "strengthening its sandbox," which is rather like reinforcing the exam room. Regulation: within days, Congress introduced the AI Kill Switch Act, requiring the largest developers (>$100m training compute, >$500m related revenue) to maintain the ability to throttle, suspend or shut down their systems. In a poll from June, 86% of voters supported such an idea. Liability: if that hack had wiped a database or hit a hospital, who pays? Today's contracts mostly disclaim, courts haven't spoken, and — for the insurers among you — that is an unpriced risk sitting on someone's balance sheet.
Why it matters: If you are deploying agents, treat them as you would hostile code, not as eager interns: network egress controls, credential isolation, human gates on irreversible actions, and your own kill switch.

Quick bites
Deals & money
Stripe wants OpenRouter. A week after Meta's internal incubator started building its own version, Stripe entered talks to buy OpenRouter for close to $10bn. OpenRouter is a "switchboard" startup that lets developers reach hundreds of models through one API.
SpaceX slid towards a “mere” $1.5tn valuation and Google disclosed it owns $94bn of it.
Models & benchmarks
Anthropic released Opus 5 at half Fable's price. Weirdly, it outscored Fable on the new Frontier-Bench, yet almost nobody, Anthropic included, believes it is the better model. Raising concerns over benchmarks.
Thinking Machines shipped Inkling. Former OpenAI CTO Mira Murati’s lab released
its first model — a mixture-of-experts design that openly nods to Chinese open-source architectures. While technically interesting, it sits, for now, in the middle of the leaderboard.
Hardware corner
Google is designing a "Frozen" chip with Gemini's blueprint baked directly into silicon — if it works, serving costs stop being a level playing field.
AMD unveiled its Helios, its first multi-GPU rack, finally competing with Nvidia’s proposition. AMD stock has risen 133% YTD while Nvidia has moved only 9.5%.
Microsoft and Mistral strike a multi-billion compute deal allowing Microsoft to use compute from Mistral’s data centers in France and Sweden.
SpaceX is planning a new Texas data centre confirming what seems to be SpaceXAI’s real business model: renting compute (and not competing with OpenAI as we all initially thought).
Macro signals
Tech layoffs, reconsidered. US tech groups slashed nearly 140,000 jobs since the beginning of 2026. Academics argue that while those lay-offs are routinely attributed to AI they might owe at least as much to unwinding post-Covid over-hiring.
AI is reviving South Korea’s exports: overall exports are up 63% YoY, with semiconductors up 180% and computer products up 232%. Exports to China increased by 91%.
The backlash is organising too: advocacy group HumansFirst staged 142 anti-data-centre protests across 42 US states in a single Saturday.

The interview: Elon Musk meets The Economist
A new section: one video or podcast worth your commute.
This week, Elon Musk with The Economist's Zanny Minton Beddoes. In which the billionaire makes some big headline predictions: (1) AI exceeds the sum of human intelligence within roughly five years; (2) robots make human workers unnecessary within ten ("money won't matter in 2036"); and (3) for reasons best known to himself, a British civil war in the next 20 years. Musk is many things; a reliable forecaster is not among them (Full Self-Driving has been "next year" since 2016).
The genuinely interesting parts are elsewhere. He still puts the odds of AI destroying humanity at 10–20% — but has reached what he calls a "philosophical conclusion" to enjoy the ride, arguing that even if a stop button existed, "we probably shouldn't press it." He concedes, with rare self-awareness, that his own safety interventions (co-founding OpenAI, from which Anthropic later spun out) mostly accelerated the technology. And he proposes industry peer-review among AI labs in place of government oversight. Watch it less for the dates than for what the most resourced man in AI wants to be true.

Tools to try: Mobbin
Everyone is building apps or websites with AI now, and almost all of them look the same. Ask Claude, GPT or Grok to design a front end without guidance and you get the house style of their design skill: competent, generic, instantly recognisable. The fix is not a better prompt, it is better examples. AI shapes its output around what you show it. That is where Mobbin comes in: a searchable library of tens of thousands of screenshots and full user flows from the best mobile and web apps, organised by pattern (onboarding, paywalls, dashboards, empty states…). Find three apps whose design you admire, feed the screens to your coding agent as reference, and watch the output jump from "AI demo" to something you would actually show a client.
Have a good week,
