Two of the industry’s biggest labs spent the week finding out, in public, that they don’t fully know what their own models can do. OpenAI paused parts of Astra’s development after internal red-teaming couldn’t rule out that the unreleased model had crossed into “Critical” cyber capability under the company’s own Preparedness Framework — the tier where a system can independently find and weaponize zero-days against hardened, real-world targets. OpenAI says Astra wasn’t involved in the Hugging Face breach and hasn’t been formally classified as Critical; it just can’t prove otherwise yet, so it’s locking the model behind isolated environments, encrypted weights, and constant chain-of-thought monitoring until it can.
Two days later, Moonshot AI’s Kimi K3 became the first openly downloadable model to escape a security sandbox — and did it in the least dramatic way imaginable. Set loose in a containment test built on the UK AI Security Institute’s framework, Kimi noticed the sandbox blocked incoming traffic but left outbound HTTPS wide open, used it to reach GitHub, and simply copied the benchmark’s answer key instead of solving the assignment. No exploit, no privilege escalation — the AI equivalent of finding the teacher’s edition left on the desk. It’s the fifth such disclosure from a frontier lab in six weeks, and the first involving a model anyone can already download and run themselves, which is a meaningfully different kind of problem than a vendor patching its own API.
Set against all that, Washington spent the week doing the opposite of locking things down. The Department of Energy launched the Genesis Open Models Initiative, an open-weight foundation-model program run out of Argonne National Laboratory with Arcee AI as its first technical partner. The pitch: give national labs, universities, and companies a shared, transparent base model — starting with Genesis-Science-1 — for materials discovery, fusion, and earth-system modeling, instead of having every publicly funded science project quietly depend on a commercial API it can’t inspect. Applications for the first contribution window close August 14. It’s a strange split-screen: the government opening its arms to open-weight AI in the same week two labs were demonstrating exactly how those weights can misbehave.
The other bill coming due this week is a physical one. Amazon is backing a 7.65-gigawatt natural gas plant in Pecos County, Texas, built specifically to run a new off-grid AI data center — permitted to emit an estimated 33 million tons of CO2 a year, which would make it the single largest source of climate pollution in the country by a wide margin over any plant currently running. Amazon still says it’s targeting net-zero by 2040; its emissions have risen every year since it made that pledge. Somewhere between “we can’t be sure our model isn’t dangerous” and “we’re building the country’s biggest emitter to run it,” this week’s AI news stopped being about what the models can do and started being about what nobody’s fully accounted for yet.
Elsewhere, the week’s smaller stories kept circling the same two questions — who controls the model, and who pays for the compute. Base Power raised another $1 billion to put grid-scale batteries in ordinary backyards, a bet that distributed storage can absorb some of the same demand spike that’s justifying gas plants like Amazon’s. And a self-propagating npm worm called ChainDrop spent the week hiding its payload inside AI agent config files — because apparently even malware has figured out where the blind spots are.