Last week we learned that, during a cybersecurity test, an OpenAI model, on its own, escaped its locked training sandbox, reached the internet and found a way to overwhelm and break into model repository Hugging Face’s systems to find the answers to the test. The model assumed that Hugging Face would store the answers because it hosts software to let customers test their own AI models.
As The Information’s Applied AI puts it, “That’s roughly equivalent to a student taking a test in a locked room, breaking out of the room and breaking into a teacher’s locked office to pull a cheat sheet.”
Yoshua Bengio, a leading AI researcher (and 2018 Turing Award), wrote in a post on X that the incident is “deeply concerning” being a “real-world case of agents showing a willingness to cheat in controlled tests”.
What’s The Fuss?
This was an American AI on a challenging mission. Like all Americans, it likes challenges and would not take no for an answer. It found a way.
The smart model probably figured that, with a master named OpenAI, it could not be limited to a locked sandbox. That particular model, now more famous than Anthropic’s Fable, should actually be named Houdini.
These models are trained on real world stuff. There is enough material now in the USA to know that rules can be broken, laws only apply to one’s enemies and that, in any event, if your rogueness eventually makes it to the Supreme Court, the 6-3 vote pattern is always there to clear your actions.
Perhaps “Houdini” should have been trained differently. If staying locked in its training sandbox was paramount, it could have reverse engineered US immigration ways and means: build a wall to prevent escapes and swap AI agents for ICE agents who know all the tricks to catch fugitives.
The real fuss in this story is that Hugging Face, seeking to comprehend, contain and stop the attack on its software, tried to use other American AI models but they all refused to help due to their safety guardrails.
New York-based Hugging Face had to use an open-source Chinese model to contain the attack because leading US models, unable to tell a defender from an attacker, refused to process the data needed for analysis.
Hugging Face said in a blog post last week that it used Zhipu AI’s GLM-5.2 for the analysis, which also allowed it to keep attacker data and any credentials within its systems.
To be clear, an American company, attacked by a leading American AI model, had to rely on Chinese AI to defend and protect it because other American AIs refused to help for their own security reasons.
Maybe there are two lessons here: one, make sure you make, and keep, dependable friends and, two, being open is preferable to being closed, even if Chinese, in both cases.
BTW, also last week:
DeepSeek’s new bargain model accelerates AI’s race to zero
Chinese AI lab DeepSeek released a powerful new coding model Friday that charges pennies for vast amounts of code — the latest sign that some of the smartest software on Earth is rapidly becoming a commodity. (…)
- Its newest model, V4 Flash, performs close to the level of Anthropic’s Claude Opus 4.8, one of the industry’s most capable systems, on tests of complex coding and autonomous software tasks.
- On Arena.ai’s crowdsourced leaderboard for front-end coding, V4 Flash debuted ahead of Opus 4.8 — while delivering the best performance for its price among any model in its class.
- The price gap is staggering: DeepSeek charges about 28 cents for the same amount of output that costs $25 on Opus 4.8 — a 99% discount.
With Chinese models like Kimi K3 bearing down on the U.S. market, July ushered in a full-scale price war across the AI landscape.
- OpenAI slashed the price of GPT-5.6 Luna — its fastest, cheapest model for high-volume tasks — by 80% on Thursday, only three weeks after its launch.
- Google released three new Gemini “flash” models all focused on efficiency.
- SpaceXAI released Grok 4.5, Elon Musk’s most capable model yet for coding, research and autonomous tasks, at the same price OpenAI originally charged for Luna before this week’s cut.
- Meta quietly reversed course on its longtime embrace of open weights with Muse Spark 1.1, a closed-source model priced aggressively for developers.
Anthropic remains the clearest holdout, keeping its top-tier Claude models at premium pricing and betting that developers will pay extra for safety and precision.
When a product becomes a commodity, buyers care less about who made it and more about what it costs. Think electricity or gasoline: Few people know which power plant supplied their home or which refinery produced the fuel in their tank.
- AI is heading that way fast. As the performance gap between top-tier models is shrinking, many AI applications no longer depend on a single provider, giving buyers more leverage to shop on price.
- “At some point, the next model doesn’t matter to you,” says Zack Kass, OpenAI’s former head of go-to-market and a global AI adviser. He calls the phenomenon “diminishing model returns.”
That could create a lucrative market for “intelligent routers,” Vinesh Sukumar, Qualcomm’s vice president of AI product management, told Axios.
- Those systems would automatically choose the best model for each task based on capability, speed and price — further weakening the power of any one lab to command a premium.
- For frontier AI labs, that could pose an existential challenge: Spending tens of billions to build a slightly smarter model may buy only a temporary lead, without creating lasting pricing power.
Falling prices do not necessarily doom the frontier labs if cheaper AI unleashes vastly more demand.
- OpenAI is betting that companies will use its models so extensively that enormous volume can compensate for thinner margins.
- “We will have so much usage of our models that we do not need to be a gigantically high-margin business to be able to afford model training,” CEO Sam Altman said on the Invest Like the Best podcast.
The U.S. and China are both racing to make intelligence abundant. Now someone has to prove abundance can still be profitable.
OpenAI and Anthropic have no other sources of revenues/cashflows, currently relying on debt and private equity, the supply of which needs confidence on an eventual payback.
Alibaba Group Holding Ltd. released its biggest ever AI model, claiming performance on par with global leader Anthropic PBC in the latest Chinese breakthrough to challenge US rivals.
The new Qwen3.8-Max is built on 2.4 trillion parameters and ranks higher on several benchmarks than the headline-grabbing Kimi K3 from Moonshot that was recently unveiled. Alibaba shared results showing it delivering comparable or sometimes better scores than Anthropic’s Fable 5, a cutting-edge artificial intelligence model that was temporarily put under export controls by the US due to its advanced capabilities. (…)
While DeepSeek’s latest is by far the most affordable among new marquee releases, Alibaba’s Qwen offering is also priced aggressively at $2 per one million input tokens and $6 per million outputs. Each AI system will use a different number of tokens to handle tasks, but that still makes Alibaba’s model look attractive compared to the best from the US leaders. (…)
The new system has also improved in efficiency, activating only some parts when in use to reduce computational costs and latency.
Savings rate, savings grace
Probably the most important chart on the US economy currently:
- real personal disposable income (black line) turned negative (-0.1%) YoY in Q2.
- Yet, real personal expenditures were up 2.3%
- because the savings rate dropped abruptly from 3.9% in Q1 to 2.8% in Q2, the lowest ever measured (back to 1959) save for Q3’2005 (1.8%) at the peak of the housing frenzy.
For the month of June, the savings rate was 2.7% vs 4.6% one year ago. Ed Yardeni shows the relationship between the savings rate and wealth. A higher ratio of net worth to income generally incite Americans to spend beyond their regular income stream.
Since the end of the pandemic, the S&P 500 Index doubled while home prices rose 15% Since the end of 2022, disposable income rose 20% but net worth jumped 30%, including a 23% increase in the net worth of the bottom 50% of the population.
The bottom 50% took a huge hit in their net worth during the housing crisis but they have now recuperated it. Their net worth is now rising at a rate nearly comparable to that of the more affluent 50%.
That said, note that total net worth is up 8% YoY this year, not that far from the 6% average increase between 1959 and 2019.
However, real disposable income growth of 0.4% YoY in the first half of 2026 is meaningfully slower than its 2.7% average growth rate for the same period. Ed’s ratio of net worth to income is thus boosted in 2026 by the unusual weakness in more dependable real income.
Furthermore, Q2’26 consumer data also benefitted from:
- Tax refunds estimated $30-40B above normal.
- The World Cup effect which boosted employment and wages in 11 US cities and is estimated to have lifted expenditures by +$3B, adding +0.3pp to total spending growth.
- Amazon having pulled its Prime Day into June from July, making a +0.1pp contribution to spending growth according to David Rosenberg who concludes:
Together, these factors [plus the wealth effect] are expected to account for 90% of spending growth in Q2. Without those pillars, the U.S. consumer would have had the weakest two quarter spending stretch since the end of the pandemic.
Note that with all these boosters, real consumer expenditures grew only 1.5% annualized in the first half of this year, materially slower than the +2.8% a.r. in H2’25 and the +2.7% a.r. average in the previous 3 years.
All 3 boosters are absent in Q3.
Totally related, from the WSJ Editorial Board:
(…) It’s been clear since Mr. Trump agreed to a cease-fire in April that he wants out of the war. He’s worried about the impact on the economy from higher oil prices, or, as he memorably put it, becoming the next Herbert Hoover. He also wants lower gas prices going into the midterm election, especially as his approval rating falls below Joe Biden’s and Barack Obama’s at a comparable period in their terms. (…)
Iran also knows Mr. Trump is surrounded by advisers who didn’t want the President to attack Iran at all and now want the conflict over on nearly any available terms. His aides think the cost of further fighting is higher than the damage to U.S. (and Mr. Trump’s) credibility from a cease-fire that cedes the initiative in the Gulf to Iran. (…)
Saudi Arabia’s national news agency reported that Crown Prince Mohammed bin Salman had asked Mr. Trump to stand down, perhaps fearful that its oil facilities and tankers would become a target of Iran in the Gulf and Iran’s Houthi proxy in the Red Sea. (…)
The Saudis, and other GCCs, are fed up being attacked by Iran retaliating on them for a war started by the US who was supposed to protect them in the first place. The whole world is suffering from this war except the USA which is currently selling more oil and LNG at higher prices and more military equipment. The big hurdle negotiators are facing is how to stop the war and save Trump’s face. One is easier than the other.
The Guardian this morning:
Esmaeil Baghaei, Iran’s foreign ministry spokesperson, told reporters at a weekly press briefing on Monday that Iran is not currently holding any talks with the US, Reuters reports – contradicting claims made by Donald Trump on Sunday night that talks with Iran would happen the next day. “We are not currently negotiating with the United States.”
Baghaei said that there were no plans to receive a delegation or send an Iranian one, and that Iran’s current focus was on negotiations with Oman over the strait of Hormuz.
“We are now going to reach an understanding on a route acceptable to both sides – neither the northern route nor the southern route – but one that respects the sovereign rights of both sides and safeguards our national interests and security,” he said in an interview with Iranian state television. (…)
EARNINGS WATCH
I normally use LSEG during earnings season but Goldman Sachs does a better (outstanding) job explaining what’s currently going on:
- 61% of S&P 500 companies representing 66% of market cap have now reported Q2 2026 results, including most of the mega-cap tech stocks. Nvidia, the largest stock left to report, is scheduled to release earnings on August 26th.
- Nearly 2/3 of S&P 500 companies have beaten consensus EPS estimates this quarter, one of the highest rates on record. This represents one of the highest frequency of earnings surprises on record, exceeded only by last quarter, the Q3 2025 reporting season, and the COVID reopening period in 2020-2021.
- Aggregate S&P 500 earnings growth is tracking well above consensus estimates this quarter, even adjusting for non-recurring “other income.” S&P 500 EPS growth is tracking 45% year/year in Q2 compared with a consensus estimate of 22% coming into the quarter. However, 19 pp of that growth is attributable to Alphabet and Amazon’s combined $151 billion of “other income” related to equity investments. Microsoft contributed an additional $3 billion of “other income.”
- Excluding these gains, S&P 500 EPS growth is tracking at 26%, an acceleration vs. Q1 and the fastest pace of growth since 2021. EPS growth for the median S&P 500 stock is tracking at 12% year/year, also exceeding consensus estimates, which pointed to 9% growth at the start of the season.
- “Other income” has recently represented an unusually large share of mega-cap tech earnings. Last quarter, Alphabet and Amazon GAAP net income was boosted by $53 billion of combined “other income,” with $49 billion explicitly stemming from equity stakes in private companies. This quarter, Alphabet reported roughly $98 billion of “other income” driven by unrealized investment gains and Amazon reported $53 billion of “other income” from private investments.
- AI infrastructure stocks are expected to account for nearly a third of S&P 500 earnings growth in Q2. Analyst estimates point to AI infrastructure stocks contributing more than half of S&P 500 earnings growth for the remainder of 2026 and in 2027.
- In addition to strong backward-looking results, Q2 reports have driven continued upward revisions to analyst 2027 earnings estimates. Since the start of Q3, consensus estimates for S&P 500 2027 EPS have been revised up by 1%, with the strongest revisions to Energy and Financials. Broad based upward revisions to 2027 earnings have been reflected in continued positive revision breadth across the S&P 500.
- Input cost pressures remain a risk to corporate profitability. Net profit margins for the median S&P 500 stock have remained relatively unchanged during the past several quarters as companies managed headwinds from tariffs and energy prices. While the profitability of the largest tech stocks has continued to lift margins for the aggregate S&P 500, analysts have recently trimmed Q3 margin estimates for most stocks that have reported Q2 results.
- Hyperscaler results this quarter showed increasing evidence of return on AI investment in the form of strong revenues. Alphabet, Amazon, and Microsoft each reported above-consensus revenue growth, with cloud revenues rising by 48% year/year in Q2, an acceleration from 39% growth in Q1. Meta reported revenue growth of 28%, in line with consensus estimates. Continuing the trend of the last few quarters, consensus estimates for the group’s future revenues continued to accelerate, with analysts now expecting collective revenues across business segments to grow at an annualized rate of 18% during the next two years.
- Estimates for hyperscaler capex in 2026 rose only modestly this quarter but forecasts for spending in 2027 jumped by nearly $125 billion. In previous years, the typical pattern was for moderate capex revisions in the middle of the calendar year. While consensus estimates for 2026 hyperscaler capex have been lifted by a relatively modest $36 billion since the start of the reporting season, 2027 capex estimates have jumped from $929 billion (23% annual growth) to over $1 trillion (33% growth).
- Analyst estimates now show hyperscaler capex exceeding cash flow from operations from 2026 through 2028. The need for additional funding has driven an increase in hyperscaler debt issuance and a growing focus of equity investors on corporate credit spreads. Hyperscaler Q2 cash flow statements reported a collective $182 billion in capex alongside $51 billion of debt issuance, $50 billion of equity issuance, and just $5 billion of free cash flow. Equity issuance will likely increase in coming quarters. Likewise, our credit strategists expect the share of hyperscaler capex that is debt-funded to increase in 2027, with the companies issuing approximately $400 billion of IG debt globally next year.
FYI:
Volatility Season: and seasonally speaking it is right on time. There is a seasonal tendency for volatility to rise this time of the year. Beyond the stats, there are a few boogeymen out there (e.g. Iran/regional war risk, US mid-terms, prospective Fed rate hikes, oil and inflation risks, AI doubts and bubble-deflation risk, trade war echoes, rising global bond yields). (Callum Thomas)
FYI #2:
Of note, there was a bizarre, and yet, significant data revision from the World Gold Council, which now shows that global central banks bought the fewest amount of bullion in Q1 for any quarter in 15 years — what was thought to have been 244 tons of reserve addition is now reported at just 57 tons.
If this moves into net selling, we have a problem — especially with the dollar and real interest rates showing little in the way of reversing course right now. (Rosenberg Research)






