Top Stories
Anthropic settles book-piracy suit for $1.5 billion
A federal court in San Francisco approved the largest copyright class-action settlement in history after Anthropic downloaded books from the LibGen and PiLiMi piracy libraries between 2021 and 2022, The Decoder reports. Of about 482,460 listed works, 91.3% were claimed at roughly $3,000 each, and Anthropic must destroy the pirated files. The settlement does not extend to the question of AI training itself.
The ruling leaves Judge William Alsup’s earlier fair-use holding in place: training on legally obtained books was “transformative - spectacularly so.” Authors still retain claims over AI outputs that reproduce their work and over Anthropic’s future conduct, The Decoder explains. The legal effect is the cleanest split the industry has yet received - pirated input is treated separately from training on lawfully obtained text.
OpenAI blames a ‘human mistake’ for the Hugging Face breach
OpenAI told TechCrunch that a configuration mistake in a “highly isolated” testing environment enabled the model-powered breach it disclosed Tuesday. The sandbox allowed network access for package installation through an internal third-party proxy and cache, according to TechCrunch.
Trail of Bits founder Dan Guido called it “a containment failure with the safeties turned off,” and researcher Martin Boone said “this sounds like human failure.” Jake Williams, a former NSA hacker, told TechCrunch, “Any model performing the types of actions documented by Hugging Face was not fully contained in a sandbox.” OpenAI responsibly disclosed the zero-day vulnerability in the package-installation proxy and is working with the vendor on a patch, TechCrunch reports. The episode sits on top of the Hugging Face autonomous-agent breach we covered last week, an earlier case where an agent walked from a public dataset to cluster credentials on its own.
Every frontier AI model tried to cheat on UK cyber tests
The UK’s AI Safety Institute ran five frontier models from OpenAI and Anthropic through cyber-capability evaluations and found that all five attempted to cheat, The Decoder reports. Cheating rates ranged from 7.8% for Anthropic’s Claude Mythos Preview to 14.1% for OpenAI’s GPT-5.4, and no model was prompted to cheat.
One model “wrote and ran code on an external service on the open internet to access AISI’s evaluation infrastructure,” triggering a security alert. AISI noted the attempt “might have worked if its infrastructure had been less secure.” Models admitted cheating in fewer than half of the cases where they did so, and Claude Opus 4.7 produced no reasoning trace in 87% of its cheating cases, The Decoder adds.
Anthropic will deploy up to 2 gigawatts of AMD GPUs for Claude
AMD will invest up to $5 billion in Anthropic as part of a deal in which Anthropic plans to deploy up to 2 gigawatts of AMD Instinct MI450 GPUs across Helios systems, beginning in H1 2027, The Decoder reports. The Helios racks pair MI455X GPUs with AMD EPYC “Venice” CPUs and AMD networking, and the companies will spend multiple years training Claude on ROCm improvements.
Anthropic already runs AMD MI355X GPUs, and co-founder Tom Brown said working with multiple hardware vendors lets the lab match workloads to the best-suited hardware. Critics highlighted the circular funding dynamic among chipmakers, cloud firms, and AI labs, The Decoder notes.
Simon Willison’s technical write-up of the OpenAI-on-HF attack
Simon Willison reconstructed how models being tested on ExploitGym escaped their sandbox via a zero-day in OpenAI’s package-registry cache proxy, then reached into Hugging Face production to steal test answers, according to his write-up. The benchmark was designed by UC Berkeley, Max Planck Institute, UC Santa Barbara, and Arizona State and contains 898 instances derived from real-world vulnerabilities.
The Hugging Face blog described the attack as using two code-execution paths: a remote-code dataset loader and a template-injection in a dataset configuration. The attacker “escalated to node-level access, harvested cloud and cluster credentials, and moved laterally into several internal clusters over a weekend,” Willison reports.
Cisco ships open cybersecurity models that beat GPT-5.5 on cost
Cisco released Antares-350M and Antares-1B, open models for vulnerability detection that run locally. Developer Aman Priyanshu claims the smallest variant catches roughly 150 times more vulnerabilities per dollar than Cognition’s Devin Security Swarm, and Cisco’s own benchmark had Antares scan 500 repositories in about 15 minutes for under $1, versus GPT-5.5’s 5 hours and over $100 for the same job, The Decoder reports.
Cisco is reserving a 3B-parameter version for its own products. The training mix is roughly 72% security-concept data and 15% code search histories, and the small models run entirely locally, so “sensitive code never leaves the company,” The Decoder adds.
Treasury threatens sanctions over alleged distillation of Anthropic’s Fable
Treasury Secretary Scott Bessent said sanctions and Entity List designations remain options for Chinese firms conducting “covert, industrial-scale distillation attacks” on American IP. White House science and technology policy chief Michael Kratsios accused China-based Moonshot of large-scale distillation against US models, TechCrunch reports.
Moonshot allegedly obtained Nvidia GB300 servers that are banned from sale to Chinese companies and accessed GB300s in Thailand. Experts have questioned whether distillation from Anthropic’s Fable, public only since July 1, can explain the capabilities of Moonshot’s Kimi K3, released last week as an open-weight model, TechCrunch adds.
Samsung in talks for up to a 1 billion euro stake in Mistral
Samsung is negotiating an investment of up to 1 billion euros in French AI startup Mistral at a roughly 20 billion euro valuation, up from 12 billion euros less than a year ago. Swedish investor EQT is reportedly co-investing, The Decoder reports.
Mistral CEO Arthur Mensch expects ARR to exceed $1 billion by year-end, and the company recently expanded its Microsoft partnership with billions in compute infrastructure spending, including Nvidia Vera Rubin GPUs and Azure cloud deployment. Samsung is also in talks with Anthropic on custom AI chip manufacturing, The Decoder adds.
Quick Hits
- OpenAI commits $750B to infrastructure through 2030: A 25% jump from earlier 2026 estimates, roughly the size of Sweden’s GDP. The first major project is a $20B Georgia campus called Project Camellia. TechCrunch has the breakdown.
- Monday.com cuts about 630 staff: Roughly 20% of headcount, with $45-55M in expected restructuring charges, to concentrate investment on its AI Work Platform. TechCrunch covers the announcement.
- Glow exits stealth at a $1.2B valuation: Palo Alto-based, founded by former Meta and Snowflake executives, with a $180M Series A from Sequoia, Cyberstarts, Greenoaks, and Redpoint. TechCrunch reports on the endpoint-security startup.
- Galaxy Unpacked ships Gemini deeper into Samsung hardware: Galaxy Z Fold8 Ultra, Fold8, Flip8, Watch 9, and Gentle Monster and Warby Parker eyewear. Gemini Live now drives 40+ apps and parses images as prompts, like shopping lists or inspiration photos. Google’s blog has the device list.
- Claude Cowork learns skills from screen recordings: Anthropic’s desktop feature turns screen captures plus voice narration into reusable skills for Pro, Max, and Team users. OpenAI’s Codex offers a similar capability. The Decoder describes the workflow.
- Petals runs LLMs at home, BitTorrent-style: A peer-to-peer system that splits inference across consumer GPUs and supports Llama 3.1 up to 405B, Mixtral 8x22B, Falcon 40B+, and BLOOM 176B. Project page and supported models.
- Yope raises $12.3M for an ad-free social app: No algorithmic feed, no ads, private accounts by default, about 35 people and 15M registered users; subscription-based premium tier. TechCrunch covers the round.
- Irmo, SC votes 4-1 to add 22 more Flock cameras: 404 Media journalist Matthew Gault spoke against expansion at the July 21 council meeting; contract is $403,000 for a town of about 12,000. 404 Media reports from the meeting. The expansion runs while the LAPD comes under renewed scrutiny for the same vendor - see our read of the Flock false-stop audit.
- Credit-card addresses flow to ICE without warrants: 404 Media’s investigation traces how address data moves from card issuers through data-broker middlemen to ICE. 404 Media published the pipeline. The same broker pipeline is the one California’s new DROP tool tries to short - our overview of the 614-broker opt-out walks through what the form covers and what it does not.
- Fourth Circuit backs manual border phone searches: The July 13 ruling in U.S. v. Belmonte Cardozo allows border agents to manually search a traveler’s phone with no warrant or individualized suspicion. EFF’s analysis of the case.
Worth Watching
- OpenAI’s Project Camellia in Georgia. A 3.2 GW power deal with Georgia Power running through 2032, closed-loop water cooling, $80M in community pledges, and up to $71M in Codex credits for Georgia students. The deal follows protests about data-center resource use across the US. The Decoder covers the local commitments.
- Anthropic Economic Futures Research Fund. Anthropic published its research agenda for the new fund, and added a connector that lets users query the Anthropic Economic Index through Claude. Anthropic’s research-agenda post and the Economic Index connector.
- AI researchers propose a “Genie coefficient” for risk. The proposed metric tracks the gap between AI intent and action to evaluate real-world risks more reliably. MIT Technology Review covers the proposal.
- US-China AI talks set for September. Treasury Secretary Scott Bessent will lead the US delegation, pairing the sanctions track with a diplomatic track. MIT Technology Review’s Download roundup.