The industry that spent two years promising ever-bigger models is now selling the tools to defend against them, and the coalitions forming around that business don't include the biggest labs. Meanwhile investors are starting to ask whether the spending underneath all of it still adds up.
Nvidia's security alliance leaves out the labs it's defending against
Nvidia said on Monday it is leading Microsoft, SpaceX, IBM, Palantir, Cisco, Adobe, Cloudflare, DoorDash and dozens of others in a new Open Secure AI Alliance, built to share open-source tools for defending against AI-driven attacks. As The Verge notes, the conspicuous absentees are OpenAI, Google and Anthropic — the three labs whose frontier models the alliance exists to guard against, or defend with.
The trigger, as covered here earlier this week, was the OpenAI rogue-agent breach of Hugging Face. What's new is the fallout: Hugging Face had to fall back on a Chinese open-weight model, GLM-5.2, to analyse the attack because built-in guardrails on US frontier models couldn't tell a defender from an attacker. Nvidia's Justin Boitano put it plainly to the Washington Post: excessive guardrails "put the cyber defender at a disadvantage". The alliance is effectively a bet that openness, not restriction, wins the security argument.
Amodei: we never asked for an open-weights ban
Anthropic's Dario Amodei spent Monday afternoon clarifying, in his own words, that "Anthropic has never advocated for a ban on open-weights models" — a direct response to criticism from Nvidia's Jensen Huang, VC Bill Gurley and former AI czar David Sacks after Anthropic sat out an industry letter opposing restrictions on open models. Amodei's real target is narrower: he wants tighter chip export controls and a crackdown on distillation aimed specifically at China, arguing authoritarian governments chasing "permanent military superiority" are the risk, not open weights themselves. It's a fine distinction that's done little to quiet the "Anthropic is protecting its business model" chorus documented by Business Insider.
Microsoft's new cyber-AI tools take direct aim at Anthropic
Microsoft unveiled MAI-Cyber-1-Flash and a platform called Project Perception on Monday, claiming its combined MDASH harness scores 96% on the CyberGYM benchmark — 12 points ahead of Anthropic's Mythos and ahead of Gemini and GPT, at half the cost of its previous tooling, according to Ars Technica. Notably, Microsoft's announcement made no mention of the Hugging Face breach and offered no explanation of what stops its own agents going the same way.
The EU AI Act's transparency rules go live for everyone, not just Europeans
From 2 August, Article 50 transparency obligations apply to any AI system operating in the EU market — chatbots, deepfake generators, emotion-recognition tools — regardless of where the company is based. Non-compliance carries fines up to €15 million or 3% of global turnover. Companies serving EU customers from London, Singapore or São Paulo are bound just the same as those in Paris or Berlin. Separately, the AI Omnibus entered into force on 27 July, pushing high-risk system deadlines out to December 2027 and August 2028 and easing burdens for smaller firms — Brussels loosening one hand while tightening the other.
Chip stocks slide as the AI spending story wobbles
Asian semiconductor shares fell as much as 7.5% on Tuesday, the steepest drop since March, with South Korea's Kospi leading declines, according to the Wall Street Journal. Two forces collided: a report that a Chinese state-backed firm has begun mass-producing advanced lithography tools, and renewed fears of circular financing after Nvidia's latest round of more than $750 billion in AI infrastructure deals. The Philadelphia Semiconductor Index has now lost more than 7% over three straight sessions.
The Hexalink view
Look at these stories together and a pattern emerges: the industry is building governance and defence infrastructure faster than it can agree on who it's for. An alliance meant to secure AI excludes the firms making the riskiest models; a lab gets attacked for a position it says it never held; a regulator's transparency rules land the same week markets start pricing in doubt about the spending that's supposed to justify all of it.
For technology leaders, the practical takeaway is to stop treating "closed" as synonymous with "safe" — Hugging Face's own defence relied on an open Chinese model when closed US ones wouldn't help. If your organisation serves EU customers, treat 2 August as a real deadline, not a Brussels problem. And if your AI budget assumptions rest on the current capex trajectory continuing unchallenged, this week's chip rout is a reason to stress-test them now, not later.
Join us tomorrow for the next briefing, or catch the five-minute audio version on the AI Storm Daily podcast.

