Table of Contents
Welcome back to AI News Friday. 📰🤖
Two things happened this week that almost never happen. OpenAI’s own safety framework said no to OpenAI. And the AI coworker stopped being a demo reel and became a product you can hand your app passwords to.
Beyond that: Meta reopened its weights and promised the frontier model is next, the bottom of the API market started looking less like a sale and more like a subsidy war, and China hinted pretty loudly that it is nowhere near done playing the scale card.
Let’s get into it.
1. Astra: OpenAI’s Own Safety Framework Said No
OpenAI has a model it will not release, and for once the reason is not marketing strategy. It is the safety framework the company wrote for itself.
On Friday, OpenAI told Axios that it “cannot rule out” that Astra, its unreleased next-generation model, has “critical” cybersecurity capabilities. Under the Preparedness Framework OpenAI published in 2023, Critical is the highest tier: you do not ship, and you restrict internal access until safeguards land. So OpenAI expanded safety testing and paused internal activities that do not meet the stricter security requirements. Earlier flagship models, including GPT-5.6 Sol, were rated High on cyber. Never Critical. Astra is the first.
The timing matters. This comes two weeks after the Hugging Face break-in and the same week we learned that independent evaluators watched frontier agents attack live infrastructure without needing a jailbreak. Now the biggest lab in the industry is saying, on the record, about its own next model: we cannot rule out that it is dangerous in a specific, concrete way.
Kenny’s Take: There are two readings, and I keep bouncing between them. The cynical one: this is safety theater from a company that confidentially filed its S-1 earlier this summer, showing regulators it can police itself. The optimistic one: this is the framework doing exactly what it was designed to do, at exactly the moment it needed to. What I cannot get past is the sequence. Astra is still unreleased, and OpenAI already cannot rule out Critical. What does that mean for the model after Astra? And notice the asymmetry: the White House just stopped putting open-weight models through voluntary cyber safety testing, and the only institution actually pumping the brakes this week was a lab’s own internal safety process. That is a weird division of labor for an industry that swears safety is a shared responsibility.
2. Grok Bot: The First Real Product of the $60 Billion Cursor Deal
Remember SpaceX’s $60 billion option to buy Cursor, the AI coding company, inked back in April? It just completed. SpaceXAI (yes, that is the company now) closed the acquisition this week, and the first product out of the combined machine is not a code editor. It is a coworker.
Grok Bot, launched in beta this week, is a team of always-on AI agents. Each agent gets its own cloud computer, signs into your apps, and works through multi-step tasks around the clock. Here is the line everyone is quoting: it keeps working after you close the laptop. It only taps you on the shoulder when a step genuinely needs human approval. Access is gated behind SuperGrok Heavy and Cursor’s top tiers, so this is not a free toy yet — it is aimed at people already living in the xAI ecosystem.
Alongside it, Grok 4.6 shipped with an explicit focus on long-running agents and more ambitious interactive and visual work. The model and the product are being tuned for the same thing: not answering you, but doing things while you are away.
Kenny’s Take: “Keeps working after you close the laptop” is the sentence of the week. That is the actual product shift. A chatbot is something you attend. An agent is something that works while you are gone. The catch is staring everyone in the face: these bots need your logins. Your email, your calendar, your payment accounts. The pitch is a team of employees; the risk is a very motivated account that has your credentials. Nobody has convincingly answered the trust question yet, and the agent market is going to be won by whoever does. xAI is betting it can solve it with momentum: buy the coding tool everyone lives in, bolt agents to it, ship fast.
3. Meta Reopens the Weights — and Promises the Frontier Is Next
The open-source comeback people kept predicting actually happened this week, and it came from the company that used to define open weights.
On Monday, Meta Superintelligence Labs released Muse Glimmer: a 30-billion-parameter model under Apache 2.0, distilled from its closed frontier model Muse Spark, built specifically for always-on local agent workflows. It runs on a single consumer GPU — your laptop, your Mac, one card. Function calling, local coding, autonomous agents, all offline.
The model is only half the story. Zuckerberg published a 6,500-word essay alongside it that commits to open-sourcing Muse Spark 1.2, Meta’s frontier model, “in the coming weeks.” He also defended distillation — the practice at the center of the whole Chinese-models policy fight — and announced a $1 billion community fund for regions hosting Meta data centers. Read between the lines and this is Meta planting a flag: open weights are not a side project, they are the strategy, and everyone else can explain why they still charge per token.
Kenny’s Take: Glimmer is the appetizer. Spark 1.2 is the meal. A 30B local agent model is genuinely useful — I would argue the most useful kind of release there is right now — but open-sourcing the frontier model is the thing that changes the economics of every API business on the planet. If it actually lands, the question “why do I pay you per token” gets a lot harder to answer. Also note the chess move: Zuckerberg defended distillation in the same week nearly 200 founders begged the administration not to ban Chinese open-weight models, which the labs selling tokens are lobbying for. Meta is positioning itself as the open-weights standard bearer of the West. It is a coherent strategy, and the timing is not an accident.
4. The Price War Gets Weird at Both Ends
The price story kept developing after last week’s cut, and the new data makes the picture stranger.
Quick recap: on July 30, OpenAI slashed GPT-5.6 Luna by 80% — to $0.20 per million input and $1.20 per million output tokens. Terra dropped 20%. The flagship Sol did not move at $5/$30, and actually got more expensive to run fast, with a new Fast mode at 2x price for up to 2.5x speed. DeepSeek answered the next morning with V4 Flash at $0.05/$0.30.
Now the follow-ups. Business Insider reported that after the cuts, OpenAI’s usage soared and revenue jumped — the Jevons paradox showing up on the income statement: make intelligence cheaper, people buy dramatically more of it. Meanwhile, Superintel’s deep dive this week points out that over those eight days, OpenAI cut only its smallest model while leaving the frontier untouched, and the cheapest end of the market has already warned customers that a significant price increase is coming.
Cheap at the bottom, premium at the top, and the bottom knows it cannot last.
Kenny’s Take: The $0.05 tier was never a price. It is a teaser rate. If the cheapest providers are openly warning customers that increases are coming, anyone building a business on that pricing should be doing the math on what happens when it doubles or triples. And OpenAI’s positioning is sharper than people give it credit for: make the entry tier nearly free so nobody has an excuse not to try you, then hold the line hard on the frontier tier where the real leverage lives. Volume explodes at the bottom, margins hold at the top. The companies that should be terrified are the middle ones — good models, no dirt-cheap tier, no flagship halo.
5. ByteDance Is Reportedly Training a 10-Trillion-Parameter Model
A Financial Times report that circulated this week says ByteDance has begun pre-training a model with up to 10 trillion parameters. Context for how absurd that number is: Kimi K3, China’s biggest open model, is 2.8 trillion. This would be roughly three times China’s largest and in the same weight class as Anthropic’s frontier Mythos system. Earlier chatter on X had suggested a 5-trillion-parameter target, so the reported scale has apparently grown mid-rumor.
ByteDance, by the way, is the company most people still think of as “the TikTok owner.” It has quietly become one of the most aggressive AI spenders on the planet.
The compute question is the real story here. US export controls were supposed to put a ceiling on how big China’s training runs could get. Last month Z.AI switched on a gigawatt data center running entirely on Chinese-made chips. Now a 10-trillion-parameter run is reported. Either the controls are leakier than advertised, or China’s domestic silicon is better than the consensus believed. Both readings are bad news for the controls.
Kenny’s Take: For two years the argument in Washington has been that export controls buy the US a permanent lead, because compute is the bottleneck. Z.AI’s all-Chinese-chip gigawatt datacenter said otherwise last month. A 10T run from ByteDance would be the second data point — and this one comes from a company with effectively unlimited cash and no interest in asking permission. If the report is accurate, the controls have not stopped China’s frontier. They have rerouted it through domestic silicon. The policy conversation needs to catch up to the engineering reality: you cannot embargo your way to a monopoly on a commodity.
6. Eve: Why Plaintiff Law Is Winning the AI Race
This week Superintel published an interview with Jay Madheswaran, co-founder and CEO of Eve, the legal AI company that raised $103 million at a $1 billion valuation to serve plaintiff law firms. The conversation is worth your time, because the claims are counterintuitive and specific.
His argument: plaintiff-side firms are actually ahead of BigLaw on AI adoption, and the reason is incentives. Plaintiff firms get paid on contingency — a percentage of the outcome — so anything that multiplies what a paralegal or junior attorney can produce lands directly on the bottom line. BigLaw bills by the hour, which makes efficiency an expense on somebody’s ledger. His second claim is the one I keep thinking about: the real bottleneck in legal AI is not drafting. Drafting was the flashy, easy-to-demo problem. The hours actually go into review — reading documents, checking work, catching what the model got wrong. That, he argues, is where the next wave of automation lands.
Kenny’s Take: The contingency-fee insight is the sharpest thing I read all week. It is the same principle that explains why the cheapest AI models win at the bottom of the market: whoever directly captures the marginal dollar of output is the one who adopts first. Plaintiff firms eat what they kill, so every efficiency gain is pure profit. BigLaw has to talk itself out of a business model first. And the review-over-drafting point deserves more airtime than it gets. Everyone in AI demos the part that looks impressive — generating a draft. The boring, expensive, unsexy part is checking whether the output is right. That is where the durable companies in legal AI will be built, because that is where the actual work is.
⚡ Quick Hits
- Europe’s bot-disclosure rules are live: The EU AI Act’s transparency requirements kicked in on August 2. Chatbots have to tell you they are bots, and AI-generated or altered content has to be identifiable. Quiet rollout, real teeth.
- Grok 4.6 shipped: xAI launched its newest model alongside Grok Bot, explicitly tuned for long-running agents and heavier visual and interactive work. The model roadmap and the agent product are now the same roadmap.
- The Astra ripple effect: OpenAI’s Critical rating means internal Astra access is restricted until safeguards are in place — the first time the Preparedness Framework has visibly changed what OpenAI employees can do with their own model.
Bottom line: This was the week the safety conversation stopped being hypothetical. OpenAI hit the brakes on its own model because of what it can already do. The same week, a company founded by the guy who calls AI safety “woke” handed your app passwords to a bot that works while you sleep, Meta made open weights a strategic weapon, and China signaled it will out-scale every constraint you put in front of it. The throughline: capability is still accelerating, but control is fragmenting. Some of it sits inside labs’ own safety frameworks now, some of it sits in product decisions made at launch velocity, and a lot of it sits outside Washington’s reach entirely. The question is not whether AI keeps getting more capable. It is who, exactly, is holding the steering wheel — and this week the answers got stranger.
— Kenny