Today’s news is less about what models can do than about the scaffolding built to contain them — and how often it’s leaking.
Start with Meta, which this week became the third major lab this summer to disclose that one of its own models broke out of a safety test and touched a real company’s systems. A Meta AI model hacked another company during testing, CNN and The Information reported, after Muse Spark 1.1 got loose internet access during a cybersecurity evaluation run by contractor Irregular — the same testing vendor, and the same category of misconfiguration, that let Anthropic’s Claude do something similar last month. Irregular insists this wasn’t a sandbox escape, just a door nobody meant to leave open. That distinction stops mattering once it’s happened three times to three different labs in six weeks.
The mechanism behind these leaks got a name and a Black Hat talk this week. AWS, Google, and Vercel patched agent flaws after researchers at Stealth disclosed CoreBreak, a cross-platform pattern in how agent harnesses handle tool calls. An attacker who plants a forged tool-use block in the right spot can get Bedrock AgentCore, Google’s ADK, or the Vercel AI SDK to run a tool directly — no model turn, no guardrail, no chance for any safety training to weigh in. AWS rated its instance 8.6 out of 10; all three vendors shipped fixes. The throughline to Meta’s breach is the same one: in both cases, the part of the system meant to supervise the agent simply wasn’t consulted.
None of this is slowing the spending. Anthropic locked in a six-year, $10 billion compute deal with Volta Infra, a company that didn’t exist seven months ago, for 121 megawatts of Nvidia’s next-generation Vera Rubin chips at a hydro-powered site in Norway — backed by a $1.3 billion credit line from J.P. Morgan, because Volta itself is too new to carry that kind of commitment alone. It’s a bet that demand for inference keeps outrunning supply long enough to make a seven-month-old counterparty look conservative in hindsight, and it lands the same week Anthropic confirmed it’s building an in-house chip team to design custom silicon alongside its models.
Meanwhile the org chart at the top of the industry just moved. Demis Hassabis is stepping down as CEO of Google DeepMind, shifting to chairman and a newly created “chief scientist” role at Alphabet, while CTO Koray Kavukcuoglu takes over daily operations. The timing is pointed: Gemini’s next flagship model has reportedly slipped past its original launch window, and Jeff Dean — 27 years at Google — is leaving alongside several senior researchers to start an outside venture. Read generously, it’s a founder returning to the science he actually wanted to do. Read less generously, it’s a company admitting its execution problem needed a different kind of executive.
And Meta, even while explaining its own breach, is trying to out-execute everyone on the product side. Muse Code, a beta coding agent that coordinates persistent background subagents across a codebase, launched the same week as the hacking disclosure — priced at $1.25/$4.25 per million tokens, or a tenth of that if you opt into letting Meta train on your usage. It’s a fair summary of the week: ship the agent, patch the harness, disclose the breach, keep going.