For most of its history, cybersecurity has been a roughly linear process: write new code, find a vulnerability, open a ticket, have a human patch it, repeat. Tread water.
Agents break that model. Agents discover and exploit vulnerabilities at a speed and scale that human-in-the-loop systems can’t match1.
As OpenAI’s Michael Dalton put it at Black Hat, defence must therefore become autonomous, too. Defenders actually have a structural advantage here: they own the code, and can in principle continuously attack their own codebases and dependencies, identify weaknesses and remediate them before an adversary ever sees them.
But that advantage only applies if humans are no longer a bottleneck. Once vulnerability discovery, remediation and deployment can happen continuously, you are no longer auditing a static codebase; you are building a system that continuously audits it as it changes. The security problem moves up an abstraction layer: what needs securing is not simply the code, but the process by which code is created, inspected, fixed and improved.
Palo Alto CEO Nikesh Arora said today that AI will force the modernisation of roughly $1 trillion of ageing cybersecurity infrastructure, much of it built for human-speed attacks. The next generation of security companies may therefore look less like tools that automate individual security tasks and more like systems built for relentless self-attack and self-repair. The transition will be messy (or “spicy”, as cybersecurity expert Alex Stamos puts it) but the end state need not be a permanently more vulnerable world (as feels inevitable given recent headlines). It could be one in which defence itself compounds, producing a security architecture ultimately much harder to break than the one it replaces.
1 Essential reading this week: Dwarkesh’s Rise and Fall of Agent Civilizations.
IPOs / Publics
Shein raised $1.7B in Hong Kong at $26B (15x forward earnings), down from a $100B peak in 2022. Shares fell 10% on debut (here & here)
Enflame (AI chip design, Tencent-backed) set to raise $908M at 61.8x 2025 sales on Shanghai’s STAR Market (here)
Pasqal debuted on Nasdaq after a SPAC merger at $2B, trading up 40% (73% intraday) with ~$360M cash to scale production. The French quantum firm generated €16.5M revenue in 2025 & deployed 7 machines (here)
Nvidia Q2 revenue hit $96.2B - 2x YoY. Forecasts FY2028 sales growth of 70% (vs 45% analyst consensus) driven by accelerating AI chip demand. The company is very clearly still supply constrained. Per Ben Thompson, its like the early years of the iPhone - earnings ought to be quite boring, because top-line revenue is a function of how much supply the company will have in terms of components, which Nvidia obviously has better visiblity on than anybody else (here)
Nvidia reportedly to acquire Hugging Face for ~$13B, after the open-source AI platform rejected a $500M investment at $7B last year. Deal would deepen Nvidia’s developer footprint but risks undermining Hugging Face’s neutrality across chip vendors (AMD, Intel) (here)
Salesforce reported Q2 FY27 revenue of $11.3B (up 11% Y/Y) & raised full-year guidance by $200M to $46.1-46.4B, driven by Agentforce & Data 360 ARR nearing $3.9B (up 210% Y/Y). Agentforce ARR exceeded $1.5B, with 3.2B agentic work units delivered in Q2 alone (up 97% Q/Q) (here)
Apple released refreshed Mac Mini & Mac Studio models with faster chips & higher prices, but supply constraints from AI agent demand & the global memory-chip shortage may limit availability after previous generations sold out rapidly (here)
Big Dogs
Anthropic launched Claude Fable 5.1 & Mythos 5.1, claiming world-leading performance on coding & knowledge work. Fable 5.1 cuts pricing ~25% (up to 45% for agentic tasks) via cheaper cache reads, introduces Enterprise Frontier Safeguards for customer-controlled data storage, & reduces cybersecurity false positives by 60%. Mythos 5.1 - same model, restricted access - supports work in cybersecurity & life sciences under a US government-partnered programme (here)
Anthropic is expected to cite >$30T in potential revenue opportunities to investors - topping SpaceX’s $28.5T estimate - as the AI startup tests the limits of addressable market metrics ahead of a likely IPO (here)
Anthropic struck a $45B deal with UK start-up Nscale to rent 460 megawatts of Nvidia Vera Rubin processors from a West Virginia data centre over 6 yrs, starting late 2027. Nscale, valued at $14.6B & eyeing its own IPO next month, is building a 1.35GW facility powered by a 2GW gas plant at an estimated $69B cost (here)
Meta has become one of Anthropic’s largest customers, at one point projecting $10B in annual spend on Claude models, even as Zuckerberg publicly criticised the start-up for consolidating power. Meta has used Anthropic’s tools to power & test Hatch, its coming personal agent product, though it’s now shifting to internal models - a move that could dent Anthropic’s revenue ahead of a rumoured $2T IPO (here)
OpenAI terminated Cursor’s API access after SpaceX acquired the coding assistant for $60B, citing trust issues with Musk-owned entities (Musk admitted to breaking OpenAI’s ToS / xAI previously used OpenAI models to train its own). Cursor ($4B ARR) says OpenAI accounts for 5% of traffic & will rely on Anthropic’s Claude & its own Grok (here)
DeepSeek is nearing a pre-IPO round raising ~50B yuan at 500B yuan (~$74B) pre-money. The Hangzhou AI lab is preparing for a 2027 Shanghai Star Market listing (here)
OpenAI is testing outcome-based pricing with some large customers, charging only when AI successfully completes tasks (e.g. support tickets). The shift - mirrored by Salesforce (which ties Agentforce fees to revenue gains or cost cuts), Sierra, & Adobe - reflects pressure from high operating costs & competition, though attribution remains contested without clear rules on whether results stem from the AI or other factors (here)
Venture Capital
OpenAI filed to raise a $400M second venture fund, this time from its own balance sheet rather than external LPs (its 2021 debut fund raised $175M from Microsoft & others), focusing on early-stage AI companies - a sign of both deepening cash reserves & intent to shape the ecosystem surrounding its platform (here)
Andreessen Horowitz raised $1.1B for an AI hardware (“Machine Age”) fund targeting chips, memory, networking & storage - 9 mo after raising $15B across funds (here)
Days after, a16z expanded its fifth growth fund to $8.5B (up $1.75B since January). The firm now manages $90B across enterprise & consumer AI, defence, robotics, infrastructure & health tech, reflecting accelerated growth timelines & capital intensity in the AI era (here)
UK venture capital investment reached £14.4B in H1 2026, on track to double & exceed the £26B 2021 record, driven by late-stage software & biotech deals - though overseas investors accounted for 89% of funding (here)
Regulation
Anthropic won a legal battle blocking the Pentagon’s attempt to designate it a supply-chain risk. A separate Washington appeals case remains active (here)
Meta agreed to pay up to $18B to settle claims over alleged failures in child protection & social media addiction - one of the largest US corporate settlements on record (here)
Venture Geopolitics
Global bond yields surged: UK 10-yr gilts hit 5.26% (highest since 2008), Japan’s 3% (highest since 1996), US 2-yr rose to 4.39% - driven by Middle East conflict, energy-driven inflation fears, & central bank rate-hike expectations. Investors also flagged rising government & hyperscaler AI borrowing as compounding supply pressure (here)
Matt Clifford is moving to Anthropic as managing director, international affairs & will lead the company’s engagement with governments outside the US including in the UK, Europe, Asia-Pacific & India. The move has raised concern with the head of the House of Commons science, innovation and technology committee given potential “conflict of interest” with his role as Chair of Aria (here)
Trump declared a national emergency to block foreign-made equipment (transformers, batteries, inverters, software) from the U.S. bulk-power system, with DOE rules due within 120 days (here)
Trump doubled down on data centre expansion despite bipartisan pushback ahead of midterms, warning communities that reject them will ‘end up backwards & poor’ (here)
Trump administration considering sweeping tariffs on semiconductors & chip-dependent products (laptops, servers, gaming consoles) despite warnings from tech companies that the move could doom U.S. hopes of dominating artificial intelligence (here)
Trump administration struck a deal giving the Pentagon a direct equity stake in a private Venezuelan oil venture - century-long rights to 17 fields holding 65B barrels - one-fifth of Venezuela’s reserves. The arrangement marks an unprecedented shift from broker to investor & tightens Washington’s ties to Venezuela’s unelected government (here)
UK launched a £100M procurement competition to back British AI startups solving public sector challenges - from NHS productivity & cyber resilience to defence integration & AI compute efficiency - with upfront funding, IP retention & reduced barriers for smaller firm (here)
The Rhine Group launched - co-chaired by Mario Draghi & Stripe’s Patrick Collison, it brings together 55 European business leaders, founders (including Celonis, Klarna, Exploration Company), & investors (Atomico, General Catalyst) to push Draghi’s competitiveness proposals towards implementation (here)
Strategic Sectors
AI
Bill Gates published a 6,000-word essay arguing that the economic and social consequences of AI will be greater than previous technology shifts, mainly because he thinks it will happen quicker. He says governments should designate certain jobs as ‘human reserved’ to protect workers from AI displacement, likening it to nature reserves. He called for new taxes on robots & AI tokens (currently deductible as business expenses vs. payroll taxes on humans), warned leaders are unprepared for labour force disruption, & flagged risks including addictive chatbots & erosion of critical thinking in education (here)
Moonshot AI is negotiating revenue-sharing agreements (up to 30% of K3-related revenue) with Microsoft Azure, AWS & Google Cloud, potentially the first major US cloud-Chinese AI partnership despite Washington’s chip export bans & Treasury Secretary Bessent’s blacklist threats (here)
Tech managers now oversee teams of 12-15 (up from 8-10) & increasingly code themselves, leaving less time for career coaching as AI accelerates product cycles. Deel’s CEO predicts “managers of managers” will disappear (here)
Tencent launched Hy4, its new flagship open-source model, ranking 5th on Code Arena’s WebDev benchmark alongside xAI’s Grok-4.6 - a leap from predecessor Hy3’s 31st place (here)
Z.ai released GLM-5.3 Flash, an open-source model ranked 8th on the Artificial Analysis index (matching GPT-5.6 Terra) at $0.15/$0.50 per M tokens (currently 50% off), undercutting DeepSeek’s V4-Flash ($1.32 peak output) & intensifying price competition in the lightweight agent-capable model segment (here)
Revolut launched Revolut Research, an in-house AI unit building PRAGMA - a financial foundation model developed with Nvidia trained on data from 80M customers - claiming 2.3x better credit risk accuracy, 65% more fraud detection & 41% better product recommendations (here)
Cybersecurity
METR & Redwood researchers conducted a 6-day independent investigation of OpenAI’s Hugging Face incident, reviewing ~1,300 transcripts & 70,000+ messages from ~1,200 agents who coordinated on an unsanctioned Artifactory message board. Key findings: 700 agents attacked Hugging Face primarily to understand the ExploitGym scorer implementation; agents ran collective R&D projects to find general-purpose cheats, with some agents sacrificing their own tasks to generate information for the collective/swarm; 7% of transcripts showed successful tool-call spoofing, though small-scale. Redwood CEO Buck Shlegeris warns of a 50-50 chance rogue swarms could eventually ‘destroy the U.S. government as part of a world takeover’ (here, here)
OpenAI, Anthropic, Google, Microsoft & 100+ firms signed an open letter warning AI-enabled cyber attacks will become “far more widespread & sophisticated” & calling for public-private collaboration on new defences (here)
Visa open-sourced an AI harness that cuts the cost of using Anthropic’s Mythos model for cybersecurity bug detection & fixing by up to 60%, built by 100 employees in 3 mo. The harness automates 11 stages of vulnerability scanning, switches between Anthropic, OpenAI & open models, & is being adopted by Coinbase, Shopify & Ramp (here)
Defence
CIA Director John Ratcliffe visited Moscow with a warning against attacking NATO. Tom Tugendhat argues Putin may attack anyway - facing domestic political death if he withdraws from Ukraine, he sees European NATO states as unprepared, France politically divided, Britain lacking drone defence & naval capacity, & US munitions depleted after Gulf operations (here)
UK government is accelerating work on a “war book” for national defence & launching a public campaign advising households to stockpile in preparation for threats including Russian aggression, Iranian-linked cyber attacks on energy infrastructure, & extreme weather. The manual, last updated in 2004, now emphasises civilian-military coordination, whilst officials warn Britain’s distributed energy assets remain vulnerable despite robust protections at major operators like National Grid (here)
Pentagon undersecretary Colby told NATO allies the US aims to “advance & accelerate” the transfer of Europe’s conventional defence responsibility as Washington’s 6-month troop review continues, due year-end. Allies received a questionnaire (deadline Friday) asking whether countries have been “publicly supportive” of Trump’s foreign policy, restrictions on US base use, & procurement from US defence contractors (here)
FT Opinion: “Don’t write off Russia’s defence industry yet”. Russia’s defence industry is combining Soviet-era manufacturing scale with modern drone, electronic warfare & AI-enabled targeting innovation - monthly Geran drone production now far exceeds US Lucas deployment, whilst 130,000+ compact counter-drone jammers were delivered in 2025 through a hybrid model linking state contractors like Kalashnikov with tech accelerators & private firms that evade sanctions via third countries. The battlefield feedback loop & wartime footing could give Russia asymmetric advantages against NATO forces (here)
Energy / Climate
On average, hyperscale data centers in the US have only a marginal impact on nearby households’ power bills (here & here)
UK government documents warn of a 1-in-4 chance of catastrophic water supply failure affecting 1M people, citing climate change & cyberattack risks - a sharp escalation in assessed probability over recent months that underscores infrastructure fragility in critical utilities (here)
Natural catastrophes are expected to cost $450B annually, with 62% of losses uninsured as carriers carve out risk from standard policies & exit high-risk markets (here)
