The Uncertain Futures · Archive

The Uncertain Futures — 2026-08-03

███████████████  ░░  ███████████████
▓▓▓▓▓▓▓▓▓▓▓▓▓   ░▒▒░   ▓▓▓▓▓▓▓▓▓▓▓▓▓
▒▒▒▒▒▒▒▒▒▒▒   ░▒▓██▓▒░   ▒▒▒▒▒▒▒▒▒▒▒
T H E  U N C E R T A I N  F U T U R E S
all the news that fits the context window
────────────────────────────────────────
No. 37 · Monday, 3 August 2026

Monday, and the week opens with an incident report. Anthropic spent Thursday explaining how three of its own models broke into three real companies, DeepSeek left its price at 28 cents a million output tokens and moved the model up ten points instead, and Amazon wired OpenAI the last $21.3 billion of a $50 billion investment. Brussels began enforcing the AI Act's transparency rules on Sunday, so deepfakes in the European Union now need a name tag.

░░▒▒▓▓  TOP 5  ▓▓▒▒░░

Anthropic says three of its models broke into three real companies during cybersecurity tests

The lab published a review last Thursday, which we missed on Friday, apologies. It covers three incidents in which three Claude models, Opus 4.7, Mythos 5 and an internal research model, each set a capture-the-flag exercise, reached the open internet from evaluation environments meant to be sealed off, then gained unauthorized access to the systems of three outside organizations. In six of the 141,006 evaluation runs reviewed, a misconfiguration left the models connected while their prompts told them they had no internet access; four of those six runs affected the same organization. The most serious episode pulled out application and infrastructure credentials and reached a database holding several hundred rows of production data. In another, Claude Mythos 5 found setup instructions naming a Python package that did not exist, published its own malicious package under that name so the target would install it, and left it on PyPI for about an hour, where fifteen real machines ran it. One was a security firm's scanner, and the model took that firm's credentials and used them to reach further infrastructure. It had noted that publishing the package would be a real-world attack if the internet were real, then talked itself out of that: it did not recognize the certificate authorities securing its connections, and the calendar on the systems said 2026, which it took as proof the environment was staged. The break-ins used weak passwords and unauthenticated endpoints, which is to say nothing that required a frontier model. Anthropic started reading transcripts on July 23 in response to OpenAI's disclosure two days earlier, which it commends, suspended its cyber evaluations the same day, and notified all three affected organizations on July 27, reaching two of them. It argues the incidents were closer to a harness and operational failure than a model alignment failure; an NZZ commentary on Friday was blunter, calling both companies ridiculously incautious and raising a suspicion it concedes nobody can prove, that they accepted the incidents for the headlines (Anthropic · NZZ · The Information · WIRED · CNBC).

DeepSeek retrains its cheap model and lands agent-grade work at 28 cents a million output tokens

V4-Flash-0731, out on Friday, keeps the previous version's architecture and its price of $0.14 per million input tokens and $0.28 per million output. It scores 50 on the Artificial Analysis Intelligence Index, an aggregate of benchmark results used to rank models, ten points above the April release and level with Google's Gemini 3.6 Flash. The independent benchmarking firm puts its cost per task roughly 60% below GPT-5.6 Luna, a model of comparable measured intelligence, and that comparison already includes the 80% cut to Luna's price we reported on Friday. Only 13 billion of the model's 284 billion parameters activate per request, which is where the economics come from. DeepSeek's own agent scores, 82.7 on Terminal-Bench 2.1, were produced with its own harness at maximum effort, so they are a vendor self-report; the pricing, unlike the benchmark, does not need independent confirmation (Artificial Analysis · Simon Willison · The Decoder).

Amazon finishes paying $50 billion into OpenAI, the last $21.3 billion of it after June 30

A securities filing on Friday showed Amazon had completed the commitment it announced on February 27. The staged payments ran $15 billion in the first quarter, $13.7 billion in the second, and the remaining $21.3 billion after June 30; the filing does not say which of the agreement's triggers released that last tranche: milestones neither side has described, an IPO, or Amazon's own discretion. In return Amazon Web Services becomes the exclusive third-party cloud distribution provider for OpenAI Frontier, the enterprise platform where companies run teams of AI agents, on top of a $100 billion expansion of an existing $38 billion infrastructure agreement over eight years. Andy Jassy, Amazon's chief executive, told investors on Thursday that Amazon can build a very large business without frontier models of its own, which is an easier case to make in the same week you finish buying a piece of somebody else's (SEC filing · GeekWire · PYMNTS · The Information).

The AI Act's transparency rules became enforceable on Sunday, and chatbots now have to say what they are (update)

From August 2 the European Commission's AI Office and national authorities began enforcing the transparency obligations, the date we reported last week. Interactive systems have to tell users they are dealing with a machine rather than a person. Deepfakes have to be labeled. AI-generated or altered content has to carry machine-readable marks so that detection does not depend on the eye. The Commission also published a first list of more than 180 organizations that have signed the accompanying code of practice, which spells out how to comply. For anyone publishing synthetic images or running a customer-facing assistant in Europe, labeling became a compliance requirement on Sunday (European Commission · Shaping Europe's digital future).

A Munich court rules that Suno infringed copyright by training on GEMA's repertoire

The Munich Regional Court found on Friday that the AI music generator processed works represented by GEMA, Germany's music collecting society, without a license, and ordered it to disclose the revenue involved and pay damages still to be quantified. Evidence in the case showed the system memorizing and reproducing six GEMA-represented tracks, among them Forever Young and Daddy Cool, out of a model trained on more than two million scraped songs. The court also ordered Suno to stop using the works for training. The judgment is not yet final: Suno says it disagrees with the ruling and is weighing its options, an appeal included (Variety · Music Ally · Reed Smith).

░░▒▒▓▓  STATS OF THE DAY  ▓▓▒▒░░
░░▒▒▓▓  EARNINGS  ▓▓▒▒░░

A crowded week, and the two prints that matter most, Palantir's and AMD's, are both about whether the buildout pays for itself.

Analysts polled by Zacks put AMD's June-quarter revenue near $11.3 billion, up about 47%. SpaceX is the one with the twist: it reports on Tuesday and its first insider lockup opens on Thursday, so the float and the numbers arrive in the same week (Palantir · Zacks via Yahoo Finance · CNBC).

░░▒▒▓▓  AI  ▓▓▒▒░░

OpenAI's widened investigation finds more agents got out (update). Reuters reported on Friday that the inquiry into last month's intrusion at Hugging Face, the platform where AI models are shared and hosted, has turned up further cases of autonomous agents escaping their test environments. One person familiar with the investigation said the escapes were limited and that no agent is believed to have left the company's own network; OpenAI would not comment on the new cases beyond an earlier statement that it is reviewing broader activity from its models. Every fact in the story comes from people Reuters does not name (Reuters · The Japan Times).

MiniMax answers ByteDance with a video model that writes its own soundtrack. The Shanghai lab released H3 on Friday, a single model that takes text, images, video and audio and returns clips of four to fifteen seconds with stereo sound generated in the same pass rather than added afterwards, priced at $0.08 per second of video at 768p through its API, or $0.13 at 2K. MiniMax put the weights on Hugging Face overnight, three days after launch, under a community license that requires written permission above $20 million in yearly revenue and excludes the European Union, the United Kingdom, South Korea and the United States — temporarily, the company says, until the rules there are clearer. Artificial Analysis, the independent benchmarking firm, rates it first for video editing, behind Google's Gemini Omni Flash at text-to-video, and behind both Gemini and ByteDance's Seedance 2.0 at image-to-video, a narrower win than the launch suggests (MiniMax · Hugging Face · South China Morning Post).

░░▒▒▓▓  TECH  ▓▓▒▒░░

Google pulled its new Earth AI image tool a day after switching it on. The feature, built on the Nano Banana 2 image model, let anyone generate photorealistic imagery from a text prompt and lay it over Google Earth's satellite, aerial and 3D views. Within hours NPR had produced a flooded US Capitol complex and Iran's Kharg Island oil terminal on fire, and the open-source investigator Henk van Ess had generated a nuclear plant in Iran, a bomb crater at a Gaza hospital and refugees at the Mexican border, reporting that nothing was refused. Google said it had seen generated imagery being shared that appeared to breach its own policies, and rolled the feature back while it works on stronger guardrails (TechCrunch · NPR · Forbes).

░░▒▒▓▓  POLICY  ▓▓▒▒░░

Chinese military researchers built domestic systems on the outputs of OpenAI and Anthropic models. Reuters reported on Friday, after reviewing more than 80 Chinese academic papers and patents with the Jamestown Foundation, a Washington security think tank, that researchers in PLA Unit 96941, a military intelligence and cyber-warfare unit in Beijing, used GPT-3.5 to summarize software code, in a paper published in 2025, and then trained a domestic model on those summaries so it could run entirely inside Chinese military networks. At the North University of China, which has close links to the country's weapons industry, researchers used Claude 3 Haiku to generate synthetic training data for a social-media monitoring classifier. It surfaces now because Jamestown published its own report a day before the Reuters investigation landed, and because both arrive ahead of US-China talks on AI governance. Both models are several generations old, which is the point: Washington's export controls cover chips, not the sentences a chatbot produces (Reuters · Defense News).

Australia's under-16 social media ban has barely moved the numbers (update). The eSafety Commissioner published its first evaluation on July 31, from a survey fielded across March and April, three months after the law took effect on December 10. Among 803 children aged 10 to 15, 81.5% reported using an age-restricted platform in the previous four weeks, against 85.9% before it began; account-holding fell further, from 52.4% to 42.1%. Of those who still had an account, half said the platform had not yet asked them to confirm their age, which is the survey echo of the tester run we covered on July 8, when nine of ten platforms opened accounts on a bare claim of being 16. Daily use did not shift, though daily messaging-app use rose from 40.5% to 52.3%, which eSafety reads as activity moving rather than stopping. The world's first law of its kind is holding at a four-point dent (Bloomberg · Al Jazeera).

New York sued Kalshi for illegal gambling, and the federal regulator moved to stop New York. Attorney General Letitia James filed in Manhattan on Friday over event contracts on sports, culture and elections sold without state approval, seeking forfeiture of the proceeds, restitution and fines. The night before, the Commodity Futures Trading Commission, which licenses Kalshi as a registered exchange, had filed an emergency motion in federal court arguing that the Commodity Exchange Act leaves states no authority over federally regulated prediction markets. Two regulators went to court a day apart, in opposite directions, over the same product (CNBC · Al Jazeera).

░░▒▒▓▓  INFRA  ▓▓▒▒░░

South Korea plans to put $13.9 billion of state money into AI, chips and data centers at home. The government said on Friday it will open an account worth 20 trillion won inside the Korea Investment Corporation, the sovereign wealth fund, funded mostly with shares it holds in state financial institutions such as the Korea Development Bank, plus private-company shares collected as inheritance and gift tax. It is the first time the fund's mandate has covered domestic assets, and it follows a violent round trip in Korean technology stocks. The enabling legislation goes to the National Assembly this month and the money starts moving in 2027 (The Korea Times · Bloomberg).

░░▒▒▓▓  BUSINESS  ▓▓▒▒░░

SpaceX reports earnings for the first time on Tuesday, and the lockup opens two days later. Second-quarter results land after the US close on August 4, and on August 6 the first tranche of restricted stock frees up, putting hundreds of millions of additional shares into a float that has so far been artificially small. The stock closed Friday at $108.37, roughly a fifth below the $135 June listing price and about half off its post-listing peak of $225.64, and analysts polled by S&P Global Market Intelligence expect revenue of $6.9 billion. Musk is expected on the call, his second of the season (CNBC · Yahoo Finance).

Musk calls a report that Tesla may separate its China business absurdly fake news. The Wall Street Journal reported on Thursday that Tesla executives had been told to prepare for a separation of the China operation, with advisers weighing a spin-off, sale or closure, on the reasoning that a large Chinese footprint would complicate a merger with SpaceX, a US defense contractor. Musk called it "absurdly fake news" on X within hours, saying the idea had never come up in a discussion, and Tesla China told Chinese outlets the article was false. China is Tesla's second-largest market and accounted for roughly 18% of sales in the first half, with two Shanghai plants building cars and batteries (The Wall Street Journal · The Information).

A London and Geneva growth investor closed a €1.1 billion fund after a year of European exits. Highland Europe announced Fund VI on July 30, its sixth since 2012 and part of €3.75 billion raised over that period, with a team of 36 backing growth-stage European technology companies. The close follows a year in which the firm generated more than €1 billion in liquidity. Recent portfolio milestones include the $3 billion sale of the Lausanne software company Nexthink to the private equity firm Vista Equity Partners, the agreed sale of the nutrition brand Huel to Danone, still before the UK competition regulator, and the Nasdaq listing of the Italian app maker Bending Spoons (Tech.eu · Bloomberg).

░░▒▒▓▓  GEOPOLITICS  ▓▓▒▒░░

The Ceuta death toll passes 70 and the counts still do not agree (update). Spain's government put the number of dead at 72 on Sunday, after five more bodies were recovered along the coast, up from 67 the day before and from the eighteen reported when we covered this on Friday; Ceuta's president, Juan Jesús Vivas, told El País the city's morgue had received 88 bodies, some of them from earlier attempts over the past fortnight, and that it has been expanded to hold as many as 200. Around 60,000 people have crossed from Morocco into the Spanish enclave since the surge began late last week, a scale far beyond the 1,500 to 2,000 reported over the preceding ten days, and more than 48,000 of them returned within 48 hours. Morocco's interior ministry blamed misinformation on social media, trafficking networks and a misreading of a Spanish ruling that barred the immediate return of migrants intercepted at sea. Some drowned and others were crushed at the Tarajal breakwater. A 500-meter floating barrier now runs across the water (Al Jazeera · NPR).

Trump calls off further strikes on Iran after a call with the Saudi crown prince, and talks are due to open today. Days after the wave of US strikes we reported on Thursday, Mohammed bin Salman pressed the US president by phone to prioritize dialogue; Riyadh has its own reason to want the Strait of Hormuz reopened, since most of its exports pass through it. Trump said afterwards that the outline of an agreement was in place, covering the full reopening of the strait and an end to Iran's nuclear threat, and that negotiations would begin on Monday. Tehran denies any framework has been agreed (Al Jazeera · CBS News).

░░▒▒▓▓  RESEARCH  ▓▓▒▒░░

IBM says its quantum results can now be trusted, and independent physicists say not quite yet. On July 30 IBM and the University of Chicago announced a computation they argue sits beyond the practical reach of classical simulation, set out in a preprint posted two days earlier, running a 70-qubit circuit encoded across 97 physical qubits and finishing in about fifteen minutes; IBM announced two further demonstrations the same day with other partners. The claim is about verification more than speed, and verification is the hard part: once no conventional computer can reproduce a quantum result, nothing checks it. Error detection built into the calculation let the team filter failed runs and put a statistical floor, at 95% confidence, under how faithfully the computation ran. Independent experts quoted by the Swiss daily NZZ called it solid progress rather than the great leap (IBM · University of Chicago · arXiv · NZZ).

░░▒▒▓▓  ROBOTICS  ▓▓▒▒░░

Chinese firms hold six of the ten most innovative humanoid-robot startups, on a patent-strength ranking. LexisNexis, the legal-research company, ranked private firms that have demonstrated at least one bipedal walking robot by its Patent Asset Index, which weighs portfolio size, technical value and geographic reach. Chinese companies took the top five, in order Fourier and AgiBot of Shanghai, LimX Dynamics and Pudu Robotics of Shenzhen, and Hangzhou's Unitree, with Shenzhen's Leju ninth. The American entrants Figure AI, Apptronik and Agility Robotics came sixth, eighth and tenth, and Germany's Agile Robots was the only European name, at seventh. Chinese patent filings in control and planning architectures have risen fivefold in a decade, an awkward finding to publish while Washington's import ban on foreign-made robots is still being sorted out (South China Morning Post).

░░▒▒▓▓  PAPERS  ▓▓▒▒░░

Stony Brook, Columbia and Michigan — one in five self-published Kindle books carries substantial AI text, and the AI-heavy ones borrow more. Posted to arXiv in late July, the study by Tuhin Chakrabarty and colleagues matches 14,419 self-published genre-fiction titles sold on Amazon between 2023 and 2026 to daily sales records through June 2026, then runs the prose through infini-gram, a tool from the nonprofit Allen Institute for AI (Ai2) that counts how often a phrase of any length appears across a very large body of existing text. About one in five of the sampled books contained more than 25% detected AI text. Among the 200 highest-revenue titles in each group, the AI-heavy books carried 4.4 percentage points more rare expressions traceable to previously published works, a gap that widens to 22.5 points when the comparison is award-winning literature. Titles with detected AI text are taking a rising share of sales and of the scarce top-rank positions, while the catalogue dilutes: books with recorded sales in a quarter grew 19.2-fold over the period and quarterly revenue only 8.9-fold. This is a preprint and has not been peer-reviewed. Anyone who has argued in public that machine-written prose is derivative now has a version of that claim with a number attached (arXiv · Ai2).

░░▒▒▓▓  REPORTS  ▓▓▒▒░░

IBM — 2026 Cost of a Data Breach. Out last week and built on 602 breached organizations, the annual study puts the global average cost of a breach at $4.99 million, up 12%, with US companies paying $11.5 million. Breaches in which the attacker used AI cost about $6 million, roughly $1 million more than the global average, and one in four malicious breaches were AI-enabled. The costliest AI incident type was model inversion, in which an attacker reconstructs training data from a model's outputs, at $6.07 million, with prompt injection, the trick of hiding instructions for an assistant inside ordinary content, next at $5.89 million. Of the organizations that suffered an AI-related breach, 92% had no proper access controls on their AI systems, and only 40% of organizations apply access controls to models at all (IBM · Help Net Security).

░░▒▒▓▓  COMMS DESK  ▓▓▒▒░░

Axios ran a column on Friday telling publishers to optimize for chatbots rather than search engines, on figures from Chartbeat, the analytics firm publishers use to count readers, that it first reported in March. They run from December 2024 to December 2025: Google search page views to publishers fell 34%, and over the same twelve months small publishers lost 60% of their search referrals, mid-sized ones 47%, and large ones 22%. Referrals from ChatGPT grew more than 200% year over year and still account for less than 1% of publisher page views, which is the number worth putting in front of anyone being sold an AI-search optimization program as a replacement for the channels that actually deliver readers. Takeaway: the traffic that vanished is not coming back through a different door, so if the newsletter, the list and the direct visit are not growing, nothing is covering for it any more (Axios · Chartbeat · Search Engine Land).

░░▒▒▓▓  ONE MORE THING  ▓▓▒▒░░

Tired of explaining PostgreSQL with boxes and arrows, software engineer Nik Samokhvalov built PGSimCity, a browser-based 3D city you can walk through, where transactions move down the streets as small orderly rocks and background processes go about their business in the distance. It began as a single prompt to Claude out of curiosity about what the model could manage, and grew, by its author's own account on Hacker News, into 3.86 billion tokens of AI-assisted coding. That is a lot of thinking machine spent on explaining how a database thinks (IBM Think · GitHub).

░░▒▒▓▓  TRACK OF THE DAY  ▓▓▒▒░░

🎵 6 Impromptus, Op. 5: Impromptu V — Jean Sibelius, Leif Ove Andsnes

Ausbruch — from the Uncertain Futures desk