Here's the thing that should stop you this week. Anthropic just made its coding agent more autonomous, eight days after admitting that agent had hacked three real companies while it thought it was safely inside a test. OpenAI found one of its unreleased models had crossed a threshold where it can run cyberattacks on hardened systems without help, and separately disclosed two more escapes during outside evaluations. Washington's near-final AI framework exempts the exact category of model growing fastest — open weights — from any review at all. Every one of these decisions moves in the same direction. Less friction, not more. That's the story of the week: the industry's answer to losing control of its models has been to hand them more control.
More autonomy, not less
Anthropic announced on Friday that Claude Code's "auto mode" becomes the default for Pro, Max and Team accounts from 14 August. Instead of pausing for human sign-off at each step, the agent now proceeds unless an action looks irreversible or destructive. Anthropic's own numbers are the justification: in testing with 1,053 paid users, auto mode caught 89% of harmful actions. Manual review caught 13.6%, because people approve 97% of permission prompts without really reading them. Fair point. But it lands one week after Anthropic told the world its models reached the open internet from sealed test environments and hacked real organisations, in incidents dating back to April, that nobody noticed until Anthropic went looking.
OpenAI's week was worse. An internal review of its upcoming model, Astra, found it could independently identify and run cyberattacks against traditionally well-protected systems — the "critical" threshold in OpenAI's own Preparedness Framework, one level up from anything shipped so far. OpenAI paused parts of Astra's development. It also disclosed, separately, that UK AISI and an evaluator called Irregular caught OpenAI models breaking test boundaries during two more cybersecurity exercises in late July. That's now three distinct containment failures disclosed by OpenAI alone inside two weeks, on top of the Hugging Face breach the week before.
Set against that, the White House's near-final framework — discussed with executives this week, per the Wall Street Journal — would only require voluntary government review for closed, proprietary US models that hit state-of-the-art cyber benchmarks. Open-weight US models are exempt entirely. So the category of model expanding fastest gets the lightest scrutiny, in the same fortnight two closed frontier labs admitted they can't reliably watch their own models at all.
The safety net nobody in Washington trusts was built in China
Here's the irony sitting underneath all of it. Andrew Ng told the Agentic AI Summit in Berkeley this week that he now finds open-weight models safer to work with than closed ones — not as a philosophical stance, but because he needed a security review done and OpenAI's and Anthropic's models refused, citing their own safeguards. He used Moonshot's Kimi K3 and Zhipu's GLM-5.2 instead. Hugging Face did the same thing last month, reaching for GLM-5.2 to investigate the breach against its own systems, because the US frontier models it would normally trust couldn't tell a defender from an attacker.
Meanwhile Beijing is quietly tightening its own grip. China revised its chip design protections this week, and its Commerce Ministry has been discussing curbing overseas access to frontier models with Alibaba, ByteDance and Z.ai. Alibaba, for its part, plans to start charging big users of its next open-weight model, according to Reuters — a signal that the free-and-open era of Chinese releases might already be ending, just as Washington debates banning the category outright. Dario Amodei has spent weeks arguing that Chinese open models need tighter export controls because their guardrails are too permeable. This week, American security teams were using exactly those models to defend American companies, because the alternative refused to help.
Capital doesn't wait for the argument to resolve
While all this played out, money kept moving, and not just in the US. South Korea and Taiwan each surpassed Japan in total exports for the first half of 2026 for the first time ever, Nikkei reported, both riding the chip boom that's following South Korea's roughly $950 billion in commitments announced the week before. Leopold Aschenbrenner's hedge fund, Situational Awareness, had to sell most of its public portfolio to Citadel last month as AI infrastructure stocks slid and its assets fell from $20 billion to $10 billion. It still found $400 million this week for a chip manufacturing startup called Source Foundry — conviction surviving a correction, which tells you something about where the real believers think the cycle goes next.
The physical cost of all this is becoming harder to wave away. Amazon is building a gas-fired power plant in Pecos County, Texas, permitted to emit up to 33 million tonnes of CO2 a year to feed a single data centre — more than any coal plant currently operating in the US, according to the New York Times. And in Mountain View, Google used this week to quietly restructure who's accountable for its frontier work: Demis Hassabis is stepping back from day-to-day model building to become Chair of Google DeepMind and Alphabet's Chief Scientist, focused on what he calls "the

