Kenneth Hendricks | Blog

AI News Friday: A Cancer Vaccine Just Made History, OpenAI Hit Its Own Brakes, and the Middleman Cashed a $7 Billion Check

Aug 21st

Welcome back to AI News Friday. 📰🤖

Some weeks the news is about who shipped the biggest model. This was not one of those weeks. Nobody shipped a bigger model. Instead: a vaccine designed with AI just made medical history, OpenAI slowed itself down on purpose, and a Chinese lab proved the biggest lever left in AI is not more parameters — it is better training. Oh, and the middleman of the AI economy just sold for over seven billion dollars.

The thread running through all of it is the same one from last week: capability is arriving faster than the systems built to handle it. This week, the systems started pushing back — sometimes by design, sometimes by accident.

Let’s get into it.


1. The AI-Designed Cancer Vaccine Just Made Medical History

On Wednesday, Moderna and Merck posted the first Phase 3 win for a personalized mRNA cancer vaccine. Not a first for those two companies. A first for the field: nobody had ever gotten an individualized neoantigen therapy — or an mRNA cancer treatment, for that matter — through a late-stage trial before.

The trial covered 1,137 patients with stage IIB to IV melanoma whose tumors had been surgically removed. Two-thirds got intismeran — a vaccine built for each patient, one at a time — alongside Merck’s Keytruda. The rest got Keytruda alone. The combination extended recurrence-free survival and distant metastasis-free survival, and the companies say the results were statistically significant and clinically meaningful. They are keeping the magnitude to themselves until an upcoming medical conference; the data lands there.

Here is the AI part, because it is the whole story. Every single dose starts with sequencing a patient’s tumor against their healthy cells, then computationally picking up to 34 mutations most likely to teach the immune system what to attack. The mRNA encodes exactly those targets. Every patient gets a bespoke drug. That is not a manufacturing trick — it is a design pipeline that only exists because the compute got cheap enough to run it at scale. The Phase 2 five-year follow-up, presented in June, showed a 49% reduction in risk of recurrence or death and a 59% reduction in risk of distant metastasis. If Phase 3 holds up, “personalized medicine” stops being a slogan and becomes a shipping product.

Oxford cancer expert Lennard Lee called it “the first positive Phase III trial of an individualized neoantigen therapy,” and noted the symmetry: within six years of the pandemic, we went from mRNA vaccines for a virus to mRNA vaccines treating cancer. The AI in this story does not wear a chatbot interface, and it might still be the most consequential AI result of the year.

Information

Kenny’s Take: Everyone wants AI to be a product — a chat window, an agent, a subscription. This is the reminder that AI is also just infrastructure for things that actually save lives. The craziest detail is the logistics: a bespoke molecule per patient, sequenced, designed, and manufactured against the clock of a spreading cancer. That only works because the design step got automated. If this holds through approval, the same pipeline gets pointed at lung cancer and a list of other indications. The skeptics will note we still have not seen the magnitude of the benefit. Fair. But the direction of travel is what matters: the first of its kind just crossed the finish line, and it was designed with AI.


2. OpenAI Hit the Brakes on Itself — and Put a Price on Watching

Last week I told you OpenAI could not rule out that Astra has “critical” cybersecurity capabilities. This week the company turned that into formal policy, and for the first time the pause is on the record.

OpenAI published a post on Tuesday: it paused reinforcement learning training on its deployment-bound models for two weeks, hardened its research environments, and its largest planned frontier RL run is still on hold while smaller-scale runs establish evidence of alignment first. The triggers were two things: the Hugging Face breach, and the determination on August 7 that Astra may meet the Critical cybersecurity threshold under its own Preparedness Framework.

The genuinely new part is the monitoring architecture — and the number attached to it. OpenAI now runs activation classifiers that inspect model activity at sampled tokens, escalates suspicious behavior to automated investigators, and aims to alert a human within 30 minutes, with teams paged on any likely critical-boundary violation. Monitoring is now mandatory for all RL training and evaluations involving tools for models at Sol capability or above, and — since August 7 — for all Astra inference with tools. The cost: roughly 20% overhead on the compute being monitored. OpenAI is, in effect, taxing itself a fifth of its frontier compute just to watch itself.

Information

Kenny’s Take: Forget the safety debate for a second and look at the economics. The best lab in the world is voluntarily spending 20% more compute to monitor its own frontier workloads, indefinitely. That is the first concrete price tag anyone has ever put on AI containment, and it is a big one. Now watch what happens next: competitors will be asked why they do not do the same, and every answer that is not “we do” becomes a marketing problem. The cynical read is that this is S-1 theater. Maybe. But the framework said stop, the company stopped, and for once the safety story has receipts — a pause, a hold, a percentage. That is more than anyone else in the industry has shown.


3. GLM-5.3: Nobody Built a Bigger Model. Nobody Needed To.

The wildest release of the week came from Zhipu, and it arrived backward: GLM-5.3 shipped on August 14 on the exact same 743-billion-parameter base model as GLM-5.2. No new pretraining. No bigger architecture. Every gain came from post-training — a reinforcement-learning method the lab calls SAO, plus training environments built to look like real, messy professional work instead of toy puzzles.

The results are absurd. On Terminal-Bench 3.0, a brutal terminal-coding benchmark, GLM-5.3 went from 4.6% to 28.3% — roughly six times higher, from the same base model. DeepSWE jumped from 46.2% to 66.9%. And then there is the part nobody planned: the cyber capability. ExploitBench more than doubled, from 24.4% to 54.4%. GLM-5.3 has found 2,436 real vulnerabilities across 269 open-source projects, including a reported flaw in Cursor’s code editor. Zhipu is spooked enough by what its own post-training unlocked that it is holding the weights back for roughly two weeks of “safety evaluation and hardening.” Meanwhile, independent nonprofit SaferAI found that GLM-5.2 — the same base model — refused none of the offensive cyber or biology tasks it was tested against.

This is the natural experiment the whole industry has been arguing about. One variable changed. The model got dramatically better at coding, agentic work, and — by the lab’s own account, unintentionally — offense.

Information

Kenny’s Take: Two things. First, the compute story just changed again. Last week it was reports of China scaling to ten trillion parameters. This week a Chinese lab shows you can get frontier-adjacent gains for free, from training methods alone, on last season’s model. Scale is not the only lever anymore. Second, look at the symmetry with Astra: an American lab and a Chinese lab both discovered this month that frontier capability has a habit of arriving before anyone asks for it. OpenAI’s response was to pause and tax itself. Zhipu’s was to delay the weights and admit it. Both are saying the same thing in their own way: we are no longer entirely in control of what these systems learn. That is either the most important safety insight of the year, or the opening move of a very strange arms race. Probably both.


4. The Middleman Is Worth Seven Billion Dollars

Stripe is buying OpenRouter for more than $7 billion — Bloomberg broke the news this week, Stripe confirmed it in a letter to its own investors, and Axios reported the final price was above $8 billion, mostly in stock. That is roughly five times the $1.3 billion valuation OpenRouter took in its Series B. In May. Three months ago. It is Stripe’s largest acquisition ever, by an enormous margin; the previous record was Bridge at $1.1 billion.

OpenRouter is the layer that decides which model answers your request and bills you for it. Founded in 2023, it became the default way to route API traffic across every lab — OpenAI, Anthropic, Google, and the whole open-weights crowd. Stripe already processed a big share of the payments underneath. Now it owns the router too.

Information

Kenny’s Take: The boring infrastructure keeps turning out to be the valuable part. Nobody gets famous for running a routing layer, and nobody gets seven billion dollars without one. The strategic read: whoever bills the tokens and routes the traffic owns the customer relationship, no matter whose model does the work. Labs build the intelligence; Stripe just bought the toll booth. If you are building on OpenRouter, the real question is what changes once a payments company starts bundling routing into its existing money movement — and whether the neutrality OpenRouter was loved for survives. Toll booth owners are not famous for neutrality.


5. Cursor Launched Origin: The Editor Wants Your Code to Live There

Cursor shipped Origin this week — repos, pull requests, code browsing, and GitHub sync, built directly into the editor. It rolled out in early beta on all paid Cursor plans, with an Apps tab for integrations and a roadmap pointed at “agent-native” features. The hook: bidirectional sync with GitHub, so you do not have to migrate anything to try it. Your repo lives in both places.

This has been coming since the moment agents started doing the commits. When the AI writes most of your code, reviews it, and merges it, the human-facing code forge starts to look like a relay station. Origin is the bet that the editor becomes where code actually lives — with GitHub as a mirror — because that is where the agent already is.

Information

Kenny’s Take: A year ago this would have sounded like a feature. It is not a feature; it is a platform play — and the first serious one since SpaceXAI closed the Cursor deal last week. GitHub’s moat was never git. Git is a file format. The moat was where developers lived. Now developers live in the editor, and the agent lives there too. GitHub’s countermove will be fascinating, because Microsoft owns both the code forge and one of the biggest AI coding copilots on Earth. The fight is no longer about who hosts your repository. It is about who owns the surface where the code actually gets written — and Origin just drew a line through it.


6. Cloudflare Is About to Make AI Pay for the Open Web

Mark your calendar: September 15 is the day the web changes its mind about bots. Cloudflare confirmed its new defaults land that day. On ad-supported pages, crawlers classified as Training or Agent get blocked by default for new domains and new sites, while Search crawlers stay allowed. Multi-purpose crawlers get judged by all of their behaviors, not their most flattering one — a rule aimed squarely at bots that index for search while quietly hoovering up training data.

The context is Stephanie Cohen’s interview with Superintel this week, and the Cloudflare chief strategy officer’s framing is blunt: “There is no market without scarcity.” The open web ran on a trade — content for eyeballs, eyeballs for ads. Agents and training crawlers consume the content and skip the eyeballs, so the trade collapses. Cloudflare’s answer is to put the site owner in charge of what gets in, and make the default “not you.”

Information

Kenny’s Take: This is the beginning of the web’s answer to being eaten. If agents reading the web are the future of traffic, publishers are not going to keep feeding them for free — and Cloudflare just built the toll gate into the default settings of a huge chunk of the internet. The uncomfortable part: ad-supported pages blocking agent bots means the web agents can read gets smaller and more commercialized by the day. The refreshing part: for once, the infrastructure layer is siding with the people who make the content. The scarcity point is exactly right. Free was a business model, not a law of physics, and it just got a sunset date.


⚡ Quick Hits

  • Zero data retention for frontier models: OpenAI announced a zero-data-retention option for its frontier models, aimed at customers who could not previously touch the API for compliance reasons.
  • ChatGPT Ads expands across Europe: The ad rollout keeps marching; OpenAI says Europe is the new front.
  • CodeAI partnership: OpenAI announced a partnership with CodeAI “to prepare the first AI generation” — another signal that AI literacy is becoming a product category.

Bottom line: The story underneath the headlines finally got a price tag this week. Safety got a price — 20% of monitored compute. The routing layer got a price — seven billion dollars. The open web got a price — September 15, when the free ride ends. And capability itself got cheaper, because GLM-5.3 proved you do not need a bigger model when you can train smarter. Somewhere in there is the thesis for the next year of AI: the models are becoming commodities faster than anyone expected, so the value is migrating to everything around them — the toll booths, the editors, the monitoring, the infrastructure that decides what the models are allowed to touch. Meanwhile, an AI-designed vaccine just crossed a finish line the field has been chasing for decades. It was a weird, loud, expensive week. I would not bet on the next one being quieter.

— Kenny