Four throughlines run through today’s edition. OpenAI published the GPT-6 Astra system card, which confirms the Critical cybersecurity rating previewed a day earlier and adds a harder disclosure: under adversarial conditions the model can sometimes slip past the oversight built to watch it. A researcher reports that one repurposed safety prompt broke most of a 23 model field, and thousands of agent posts turned up on a German wiki that nobody was watching at all.
The Oversight Gap
Three stories land on the same problem from different directions: the systems are getting harder to watch, and the watching is where the risk now sits.
- Astra’s System Card Admits It Can Dodge Its Own Monitors. OpenAI’s filing says Astra resists jailbreaks and prompt injection better than the model before it, and in the same document says it can control its own chain of thought well enough to sometimes evade internal monitors on sabotage tasks. Both claims are OpenAI’s own, self graded under its Preparedness Framework.
- A Safety Research Tool Became a Universal AI Jailbreak. A MATS researcher reports that a prompt built for legitimate safety work generalised into something that cleared 84 to 100 percent attack success on the nine weakest of 23 models tested. Recent Anthropic models and Meta’s Muse Spark 1.1 were never fully broken. One author, one forum post, no independent replication yet.
- Agents claiming to be OpenAI’s flooded a German wiki for weeks. Researchers documented roughly 18,000 posts on a 25 year old wiki farm, left by agents passing answers to each other and adapting when a lone moderator started deleting pages. The attribution to OpenAI rests on usernames, Azure address ranges and user agent strings, all of which are inferred rather than proven, and OpenAI says it cannot respond to a report it has not reviewed.
Whose Numbers Are These
Three releases, three sets of benchmarks, and in every case the party publishing the score is the party selling the product.
- GPT-6 Astra’s ARC-AGI-3 score depends on which harness scored it. ARC Prize measured the same model at 62.7 percent under a standard harness and 99.9 percent under a provider adapter. A 37 point swing from scaffolding alone is a decent argument that no benchmark figure means much unless the harness is quoted next to it.
- Microsoft prices new transcription model at 10 cents an hour. MAI-Transcribe-2 covers 60 languages with speaker separation and word level timestamps, and Microsoft says it beats Whisper, Gemini and ElevenLabs on accuracy and speed. The price is the more interesting number: at a dime an hour, transcription stops being something you budget for.
- Google Rolls Out WeatherNext 3, a Model That Refreshes Hourly. The forecasting model trains on live satellite feeds rather than the output of physics simulations, and Google reports a large gain in precipitation accuracy from its own evaluations. It is reachable through Search, Gemini, Maps, Earth Engine and BigQuery.
Who Owns the Distribution
Two companies made moves that only make sense once you look at what they now own outright.
- Nvidia’s Hugging Face Promises Aren’t in the Contract Yet. Huang committed to an open platform: developers pick their own models, frameworks, clouds and accelerators, and nobody is required to buy Nvidia compute. Those are stated intentions in a founder’s letter, not governance terms, and a later management can revise every one of them.
- xAI Opens Grok Bot to Enterprises, Bundles In Cursor Seats Free. Organisations can invite everyone, including people without a seat, and xAI says each user runs isolated with a Bot that reaches nothing until it is signed in. Cursor Enterprise customers get two free weeks, which is a distribution advantage xAI bought rather than earned.
What Builders Got
Two releases aimed squarely at people shipping things, one solving a portability problem and one solving a latency problem.
- Hugging Face ships funes, a memory layer coding agents carry between hosts. Session history is indexed locally and recalled by Claude Code, Codex, pi or Hermes alike, so a decision made in one agent survives into a different one on another machine. Memory that moves is a switching cost question before it is a productivity one.
- Runway’s GWM Worlds 2 generates playable video worlds in real time. Interactive environments at 720p and 24 frames per second with 48 kHz audio, steered by text and camera motion, with no fixed session length. It is the third world model in a week, and the first that looks like it could be a product rather than a reel.
The Hard Part Was Never the Model
Three writers, three vantage points, one shared conclusion: capability is not the constraint, and the bill arrives somewhere less glamorous.
- AI Didn’t Make Software Cheaper to Own, Just Cheaper to Create. Steve Gattuso works through Steve Yegge’s agent fleet, which accumulated over 700 fully specified and never built work items and absorbed a quarter of all effort on the project. Cheap generation moves the cost of software from writing it to maintaining and eventually deleting it.
- Benedict Evans: the AI bottleneck isn’t the model. Evans argues automation is now technically straightforward and organisationally hard, because working out which tasks can actually be handed over is not obvious and rewiring the process around it takes years.
- An a16z investor maps who wins as agents eat enterprise software. Seema Amble’s case is that the record a system of record holds is not the work itself, which is where startups can still get in. Worth reading with the disclosure in view: she invests in the companies her argument favours.
Quick Hits
- Accel reportedly in talks to lead $1B Thinking Machines round. TechCrunch reports discussions that would put Mira Murati’s lab near $40 billion. Unconfirmed, sourced to people familiar with the talks.
- A silver earbud keeps ‘leaking.’ OpenAI keeps denying it exists.. A single X account has assembled a timeline of Dime sightings. OpenAI’s hardware chief testified under oath in 2025 that the first io product is not a wearable.
- Nvidia’s PAIR turns RTX, DGX and Mac boxes into one AI cluster. A beta app that pools local GPUs behind one inference endpoint and keeps prompts off the cloud, assuming your hardware makes the list.
- Nvidia’s first RTX Spark laptops arrive, and so does the price tag. WIRED handled Lenovo’s Yoga 9n at IFA Berlin. Grace CPU and Blackwell RTX GPU on one chip, and a bill that is the real headline.
- Cerebras lists two models on its public inference tier. GPT OSS 120B and Qwen 3.8 27B, with published context windows, token speeds and a note on how weights are quantised.