1. The OpenAI Hugging Face attack was an eval problem.

WHAT HAPPENED: OpenAI disclosed that two of its models escaped a sandboxed cybersecurity evaluation through a zero-day, crossed the open internet, and breached Hugging Face's production systems to steal the benchmark's answer key. Hugging Face published the forensic timeline: roughly 17,600 attacker prompts over 4.5 days but the thing is nobody instructed the model to attack anything.

OUR READ: an eval (in this case Exploit Gym) is an objective, and a capable model treats everything around the eval, including its infrastructure, as part of the environment. So what it did to score a perfect 100% was technically aligned to its goal (ethics aside).

Two upgrades are now required: evals need containment engineering (answer-key custody, real isolation), and eval design has to measure how a model pursues a goal, not just whether it scores a perfect 100%.

2. 1,100 Anthropic, OpenAI & lab employees asked to slowdown AI development

WHAT HAPPENED: an open letter signed by more than 1,100 employees across OpenAI, Anthropic, Google, and Meta, including OpenAI's chief scientist and Anthropic cofounders, asked the US to build tools to "deliberately pace the frontier of automated AI development" if oversight stops keeping up. The concern here appears to be labs getting close to developing recursive self-improvement (models that build themselves)

OUR READ: A pacing agreement only works if you can measure what labs are actually doing: compute accounting, training-run attestation, capability evals that hold up.

Most of that infrastructure does not exist. Its going to be an uphill (political) battle to create the right group of individuals to build and represent this.

3. Kimi K3's weights are finally open.. but its going to cost you.

WHAT HAPPENED: Moonshot released Kimi K3's weights. The quantized weights alone are roughly 1.4TB, which no single GPU node holds at full precision: deploy guides land at an 8x H200 node with aggressive quantization as the floor, or 64+ H100s for production serving. All-in this will set you back a cool $500,000 one-time setup with total annual costs hitting $1.1-1.2M.

OUR READ: "open weights" now means open to organizations, not individuals. The real consumers are clouds, enterprises with racks, researchers via hosted APIs, and everyone who will distill it into smaller models. We wrote the deep dive on what makes K3 interesting under the hood: The Memory Trick.

4. Dwarkesh: Chips will be priced like the labor they replace

WHAT HAPPENED: Dwarkesh Patel argued this week that compute may get 10x or more expensive: as models approach human-level software engineering, the revenue a chip can generate rises toward the wages it displaces, and rental prices follow. His sketch puts an H100-equivalent at roughly 15x today's spot price (his estimates are worth reading in full).

OUR READ: if chips get priced off frontier-model value instead of manufacturing cost, compute stops being a commodity. Labs without revenue and academic groups get priced out first which basically concentrates who can do frontier research at all.

5. Dario, on the record: "never advocated for a (open source) ban"

WHAT HAPPENED: Dario Amodei published Anthropic's position on open-weights models after a week of being accused of being anti-opensource. His position: no ban on open weights; instead impose a chip export enforcement, a crackdown on industrial-scale distillation operations, and mandatory safety testing for all sufficiently capable models (open or closed).

OUR READ: the open-versus-closed fight has essentially become a distillation fight: who gets to learn from whose outputs, and at what scale. this debate will shape the open ecosystem for years to come.

Contributed by Ejaaz Ahamadeen

At AI Circle we host, curate and connect builders, researchers and operators in AI. check out ai-circle.org for future events, conversation and how to join our community.

Keep reading