Two stories this week, connected by one word: open. A Chinese open-weight model helped touch off the worst week for chip stocks since April, as investors finally asked what $725 billion in AI capex is buying. Days later, when an autonomous agent breached Hugging Face, its own defenders were locked out by US frontier-model guardrails and ran the forensics on an open Chinese model instead. On both fronts the closed American frontier bet had a bad week, and open weight was the common winner. Meanwhile Washington spent the same week making the closed models harder to buy at all. Below: the sell-off and its trigger, AI on both sides of the security desk, and the state moving inside the stack.

Sponsor

In the Wild

What's trending in AI right now, from the app charts to the community feeds. Full roundup in the latest In the Wild.


Quick Hits

DeepSeek's Quiet Takeover

The trade got repriced last week, and the catalyst came from China.

AI Supply Chain Under Siege

What the Hugging Face breach revealed about US guardrails, and a WordPress hole now under active attack.

  • Hugging Face's defenders got locked out of US AI, so they turned to an open one. After an autonomous agent breached its clusters, Hugging Face tried frontier models behind commercial APIs to analyze the attack and got blocked by their safety guardrails, which it says cannot tell an incident responder from an attacker. It ran the forensics instead on GLM 5.2, an open-weight model, on its own hardware, so no attacker data or stolen credentials left the building.
  • A 500-million-site hole in WordPress core just got public exploits. The wp2shell pre-authentication RCE is an anonymous request that runs code on a default WordPress install, tracked as CVE-2026-63030 and CVE-2026-60137 and patched in 7.0.2 and 6.9.5. Searchlight Cyber found the chain, which it estimates exposes more than 500 million sites, and public proof-of-concept exploits are now circulating.

The Year Governments Got Serious

While China gives models away, three governments moved to control who gets the closed ones.

  • The White House now approves who can buy frontier AI, customer by customer. The Trump administration is directing which companies get access to the latest models from OpenAI and Anthropic, CNBC reports, a decision that used to sit with the labs. It blocked Claude Mythos 5 and Fable 5 on national-security grounds before reinstating access, and Sam Altman told staff the government is now approving GPT-5.6 customers one at a time.
  • A CIA officer spied on the UAE's AI champion, then helped it win US chips. The Wall Street Journal reports that Jonny Gannon investigated G42's China ties under diplomatic cover, then became the channel through which Abu Dhabi learned what Washington wanted, and the UAE ultimately secured expanded access to Nvidia's advanced chips.
  • The EU Parliament is becoming a frontier-model buyer of its own. Politico reports the Parliament will roll out an in-house "EPGenAI Hub" as early as September, giving MEPs and staff sanctioned access to models from OpenAI, Anthropic, Meta and Mistral through a single interface, an attempt to bring lawmakers' unofficial AI use under governance.

Open Weight Won Both Fights

Line up this week's two big stories and the winner is the same on both. The model that helped reprice the US AI trade was open-weight and Chinese. The model that did the forensics US frontier APIs refused to run was also open-weight and Chinese. Kimi K3 is closing the capability gap at a fraction of the price, and GLM 5.2 handled incident-response work that US frontier models' safety filters blocked, because a hosted guardrail cannot tell an attacker from a defender. Both stories point the same way. When the closed frontier bet gets too expensive or too locked down to use, the open alternative is sitting right there, and more and more it's Chinese.

That alternative is now drawing institutional money. This week the nonprofit Current AI said it has $400 million in commitments to build public, open AI infrastructure, including $100 million from France, on the argument that a technology this important needs a public option. The irony sat one section up: the same week open weight won on Wall Street and at the security desk, Washington was deciding who is even allowed to buy the closed American models.

Key Takeaways

  • The AI trade got repriced last week, and the catalyst came from China rather than a US lab. Chips had their worst week since April as investors started auditing $725 billion in capex.
  • The security desk showed the same pattern. When an autonomous agent breached Hugging Face, its defenders were blocked by US frontier-model guardrails and ran the forensics on an open Chinese model instead, the same week a 500-million-site WordPress hole went under active attack.
  • The state moved inside the frontier stack. The White House approves frontier-model customers one by one, a CIA officer brokered the UAE's chip access, and the EU Parliament is standing up its own AI hub.
  • Open weight was the week's common winner, and it is drawing institutional money: Current AI now has $400 million to build a public alternative.

Worth Reading

Watch This Week

AI Weekly is now on YouTube. The week's sharpest stories, each under 40 seconds:

Useful? Subscribe on YouTube. We post several a day.

Wait, What?

Worth Watching

The videos AI practitioners are passing around right now — curated on AI TV.

We Are Living in a ‘ChatGPT Flyer Pandemic’
404 Media
Sundar Pichai on A.I. Backlash, the Future of Work and Google’s Next Era
Hard Fork

This week's poll

Open weight won on Wall Street and at the security desk this week. Where's the durable edge a year from now?

Last week, 364 of you voted:

**Twelve months from now, your organization's AI spend is:**

  • Bigger, and clearly paying off42%
  • Bigger, and still unclear if it pays off18%
  • Smaller, capped by usage limits21%
  • Flat, mostly moved to open-source20%

See full results →

**Open weight won on Wall Street and at the security desk this week. Where's the durable edge a year from now?**

Back Wednesday.

Alexis