Latest AI News

Judge says Trump admin still lacks evidence for Anthropic ‘supply-chain risk’ label
During a Thursday hearing, a judge said the Trump administration hasn’t presented enough evidence to justify labeling Anthropic asupply-chain riskand banning the federal government from using the company’s technology. BloombergandAxioswere among the first to report the news. The dispute stems from stalled contract negotiations between Anthropic and the Department of Defense.Anthropic saidit didn’t want its AI used for mass surveillance of Americans or for targeting or firing decisions involving lethal weapons, arguing the technology wasn’t ready. The Pentagon countered that a private company shouldn’t dictate how the military uses technologies, and said it would use the tools in “lawful” ways. The government has also argued that Anthropic’s public criticism of the DOD justifies the ban — logic that U.S. District Judge Rita Lin called “really troubling,” warning it could set a precedent of retaliating against federal contractors who disagree with the administration. The DOD further claimed Anthropic could potentially disable or alter its AI models during warfighting operations — a claim that experts saylacks evidence. Lin agreed, saying she saw no proof Anthropic could alter a delivered model or “flip some kind of kill switch.” Thursday’s hearing was part of one of twolawsuits Anthropic filedagainst the DOD in March, challenging the ban and risk designation. The other is being heard in Washington. Lin, who temporarily blocked the ban in March, is now weighing whether to make that order permanent.
View

Investors love AI, as long as you’re a cloud host
Amazon reported better-than-expected second-quarter earnings on Thursday, and investors loved what they saw. Net sales rose 20%, and cloud revenue stood out as a particular bright spot. This combination of positive results was enough to send Amazon’s stock up nearly 10% in after-hours trading. Crucially, Amazon isn’t slowing down on data center spending, despite the conventional wisdom that investors want companies to rein it in. One line item, in particular, illustrates Amazon’s appetite for investing in infrastructure. Amazon spent $173 billion for the fiscal year ended June 30 on property and equipment — a category that covers GPUs, natural gas turbines, and plots of land — up from $107.65 billion from the year before. It also raised its 2026 capex forecast from $200 billion to $220 billion — even as it has begun dipping into its cash reserves to help cover the cost. The company ended the quarter with $7.6 billion less cash than it had 12 months ago, marking its first period of negative free cash flow this year. Under normal circumstances, ballooning expenses would be a tough pill for investors to swallow. But Amazon has a revenue engine that helps justify the spending. AWS revenue rose 37% year over year, clocking $42 billion for the quarter. That’s not enough to balance out the capex spending in raw arithmetic, but it shows that demand is growing alongside supply. Given the years-long time lag between breaking ground on a data center and selling its capacity, that’s reassuring for investors. Critically, Amazon’s AI play isn’t limited to building large data centers. The company is also making serious long-term bets on chips like the Trainium TPU and the Arm-based Graviton processor. Those projects don’t show up in capex numbers, but they can meaningfully improve margins for the company’s cloud business. “We see the AI business following very much the same margin trajectory we saw in the core business before,” Jassy said during the company’s Q2 earnings call. “AWS and Amazon Bedrock can have a wildly successful business without its own frontier model, and the reason is that there’s not going to be a single model to rule them all.” This dynamic isn’t unique to Amazon. We saw similar patterns atMicrosoftandGoogle, whose shares also popped after reporting strong cloud revenue. By the same token, companies likeMetawhich have significant capex and no clear revenue source, are still experiencing intense skepticism from investors. Meta’s stock fell 8% after earnings this week, as investors focused on its cash flow crunch and continued spending. Of course, investors like revenue and don’t like expenses — that’s how markets work. But it’s important not to miss the broader lesson about the AI economy. Right now, investors are treating cloud hosts as the most reliable part of the AI stack, while remaining skeptical about the underlying economics for AI labs and AI startups. But Amazon’s hosting revenue is someone else’s AI bill. In Anthropic’s case, it’s literallythe same money. If that spending isn’t sustainable for the big labs and their clients, the revenue won’t be stable for Amazon and the other cloud hosts. There’s real competition and differentiation at every level of the stack, but if demand for AI doesn’t hold up, it’s going to be a bad time for everyone. In the end, it all comes back toDavid Cahn’s $3 trillion question. There’s either enough demand to justify this buildout or there isn’t. Cloud-hosting services like AWS may be a few steps removed from that demand problem, but that doesn’t mean they’re insulated from it.
View

AI hedge fund Situational Awareness may have sold its public portfolio, but it still has its Anthropic shares
Situational Awareness, a hedge fund formed by former OpenAI researcher Leopold Aschenbrenner, has sold the majority of its public stock portfolio to Ken Griffin’s Citadel following steep losses over the past month, the Wall Street Journal reported earlier on Thursday. It’s a big comedown for the rising star who has beendescribedas both “scarily smart,” and “brash.” German-born Aschenbrenner, who is 25, had no prior trading experience before launching the fund in 2024. He gained prominence for his investment thesis after publishing essays arguing that scaling AI would require a major build-up in semiconductors, compute, memory, and energy infrastructure. He joined OpenAI’s “superalignment” team in 2023, two years after graduating asvaledictorianfrom Columbia at 19 (he enrolled at age 15). But he was dismissed from the company a year later over what it described as an improper disclosure of internal information. At the time, that team was led by OpenAI co-founder Ilya Sutskever and AI researcher Jan Leike. Soon after, Sutskever left tostart his own company, Leikejoinedrival Anthropic, and Aschenbrenner launched his fund. Things couldn’t have been going better for Situational Awareness until very recently. The fund returned439% for the yearthrough June, the Financial Times reported. Assets under management reportedly grew to as much as$45 billionduring their peak before the fund’s positions began dropping sharply amid a broader decline in AI infrastructure investments, CNBC reported. Even after losses mounted, Aschenbrenner didn’t flinch. In a July 24 letter to investorsseen by the FT, he called the selloff one of the best buying opportunities since early last year and invited clients to commit fresh capital starting August 1. According to Bloomberg, the appeal didn’t garner the commitments he’d hoped would materialize. Some of the hardest-hit stocksheld by the fundincluded memory chip producers SK Hynix and SanDisk, clean energy developer Bloom Energy, and neocloud provider Nebius Group, all of which have plummeted by more than 30% over the past month. AI infrastructure equities fell as public investors grew concerned that massive capital expenditures weren’t translating into near-term revenue. The fund’s losses were amplified by leverage, a common hedge fund strategy of using borrowed money to buy stocks. After Citadel bought the bulk of those holdings, Situational Awareness’ overall assets fell to roughly$10 billion, Bloomberg reported, down from around$20 billionin recent months, per an earlier WSJ report. Situational Awareness raised several hundred million dollars at its outset. Early backers of the fund include quant-trading firm Jane Street, Stripe co-founders Patrick and John Collison, and Meta executives Daniel Gross and Nat Friedman. Citadel’s purchase fits a familiar pattern for Citadel. Ken Griffin’s hedge fund has a reputation for stepping in to snap up attractive assets when leveraged players are having to unwind themselves. Even before picking up some of Situational Awareness’s holdings, Citadel’s portfolio featured some of the sameAI infrastructure bets, suggesting that, like Aschenbrenner, Griffin expects the sector to recover and has the ability to wait it out. Situational Awareness did not, however, sell its investments in private companies, according to multiple reports. Most notably, it continues to hold a stake in Anthropic that’s right now valued at $5 billion, according to Bloomberg, and which many would view as an asset that continues to appreciate. Indeed, Anthropic was last valued at $965 billion in a Series H round in May, and it’s expected to go publicas soon as October, potentially at an evenhigher valuation. It’s conceivable that a windfall from the sale of those shares could offset some of the hedge fund’s public-market losses. Other private investments in the portfolio of Situational Awareness includechipmaker MatXand AI data center startup Fluidstack, which was reportedly in talks in April to raise a new round at an$18 billion valuation. TechCrunch has reached out to Aschenbrenner for comment.
View

Meta says AI is making it easier to build new apps — and more are coming
Meta is using AI to quickly launch apps, and more are on the way. During this week’s second-quarter earnings call, Meta CEO Mark Zuckerberg said the social giant has new apps in the works, following a recent spate of other launches that included anapp for Marketplace sellers,one for Facebook Groups, a vibe-codedgaming app, a newphotos app from Instagram, and anexperimentinvolving AI bedtime stories. Meta has spent years trying and failing to produce new, stand-alone social apps to complement its core platforms. Now, the company says that large language models (LLMs) make it possible to ship software faster, allowing it to test new ideas at a quicker pace. “I’m … excited about how AI is helping our teams speed up product development,” Zuckerberg told investors on Wednesday’s call. “Earlier this year, we shipped Instagram Instants. We also just launched Forum, a stand-alone Groups app, and Seller, a stand-alone Marketplace app. I expect it to become a lot easier to ship new apps. So we are planning to build out more ideas and use our recommendation systems to scale them,” he said. “AI is improving our core business; it’s making our apps more relevant and delivering better results for businesses. We’re starting to deliver more novel products, and we’ll have a lot more there soon as well,” Zuckerberg said. Meta has been down this road before. In its earlier days, Meta (then known as Facebook) ran an internal incubator called Creative Labs, which aimed to test new social concepts. That effort produced a handful of launches: the photo-sharing appSlingshot, the anonymous chat appRooms,a Flipboard competitor calledPaper, the Moments photo-sharing app, and a collaborative video app known as Riff. Those experimentscame to an end in 2015, and the apps were eventually all shuttered, as the company struggled to find an audience for its efforts. In the early 2020s, Meta tried again, this time with an internal R&D group,NPE Team, which tested apps that included the chat app Bump, social music app Aux, task appMove, dating appSpark, calling appCatchUp, zine makerE.gg,events appVenue, creator Q&A appHotline, Cameo competitorSuper, couples appTuned, music appBARS, and others. Again, none became a breakout success, and the apps were shut down. Now Meta can point to at least one example of how AI is helping new apps scale. It has finally delivered a modest hit with Threads,which now has 500 million monthly active users. Zuckerberg likes to say Threads will one day become the company’s next billion-user app. With Threads, Meta learned toheavily lean on its existing user baseto help initially seed the app with people, then continued to heavily promote it across its existing platforms, including Facebook and Instagram. But LLMs are another key factor in Threads’ growth, as the company said it sees “significant gains” from its AI-powered content recommendations. “We are finding that LLMs are increasingly capable of delivering ranking and recommendations gains,” Meta’s CFO Susan Li told investors on the call. “First, they make our existing systems smarter by understanding what the content is actually about and generating better training data. Second, LLM-powered agents are also helping with engineering development by evaluating content quality, detecting trends, and testing ranking changes.” Li added that earlier this year, Meta reached a milestone: Every Reel and Feed post on Instagram is now automatically processed through an LLM and analyzed for topic and tone, which helps improve recommendations. The company is also developing LLM-native recommendation systems, which could help it to better scale new apps as they arrive. Investors didn’t follow up with company executives to ask more questions about the new apps Meta has in the works, as they were more concerned with AI spending and Meta’s growing enterprise ambitions. However, Zuckerberg suggested that people won’t have long to wait to see what’s next, saying the “new consumer products” were “releasing soon.”
View

Okta buys AI security startup Permiso; source says for about $200M
Okta on Thursdayagreed to acquireAI identity security startupPermiso Security, betting that demand for protecting AI agents and other machine identities will grow as enterprises deploy autonomous software across their operations. The identity management company did not disclose the terms of the transaction. But TechCrunch has learned that the acquisition is valued at just under $200 million and is structured as an almost all-cash deal, according to a source with knowledge of the deal. A spokesperson for Okta did not dispute the $200M figure when TechCrunch asked CEO Todd McKinnon for comment about the deal, but the company would not comment on specifics of the deal terms. The deal is expected to close in the third quarter of its fiscal 2027, Okta said, subject to customary closing conditions. Okta’s move to buy Permiso comes as identity management companies seek to expand beyond verifying users at login to continuously monitoring what users, applications, and AI agents do once gaining authorized access to a network environment. That shift has intensified competition to secure machine identities as enterprises embed AI deeper into everyday operations. Permiso, whichemerged from stealth in 2022, develops software that helps security teams spot suspicious activity in cloud environments after users or applications have been granted access. More recently, the startup has expanded its platform to monitor AI agents and other machine identities. Co-founded by former FireEye executives Paul Nguyen and Jason Martin, Permiso specializes in detecting attacks that use stolen or compromised identities to move through cloud infrastructure. In April, the startup alsointroduced SandyClaw, a platform designed to analyze AI agent skills in a sandboxed environment to identify malicious behavior before they are deployed. The deal strengthens Okta’s push into securing AI agents and other non-human identities alongside its core identity management business. “Permiso will extend Okta’s identity security fabric with proven identity threat detection and response capabilities, and an incredible threat research and security team that will advance Okta’s threat detection and prevention capabilities,” Okta’s chief product officer Ely Kahn said in a prepared statement. Permiso has raised about $29 million to date, including an$18.5 million Series A roundin April 2024 led by Altimeter Capital. People familiar with the financing said the Series A valued the Palo Alto-based startup at about $80 million on a post-money basis.
View

LinkedIn adds a button to report AI-generated ‘slop’
LinkedIn is taking aim at the “AI slop” — low-quality, artificially generated content — filling its feed. On Thursday, the company announced that it’s adding a new feature to let users click a “seems like AI slop” button when someone’s post appears to have been written with AI. The move reflects a broader shift across online publishing platforms to cut back on AI content, as people have grown frustrated with the computer-written, inauthentic posts filling the web. Last week, for instance, newsletter platformSubstack added a toolto help users identify when the content they’re reading on its site was written by AI, through a partnership with Pangram. Meanwhile,Pangram this week announced $9 million in new fundingto tackle the problems of AI content flooding the internet. The problem is also impacting new startups, asDigg had to shut down its Reddit competitor in March,saying it couldn’t get a handle on the number of bots flooding its site. Internet infrastructure firm Cloudflare says the problem is just getting worse, asthere is now more bot traffic on the webthan human-generated requests — a milestone that wasreachedfaster than it had previously predicted. Ina post on LinkedIn, the company’s Chief Product Officer Hari Srinivasan admitted the Microsoft-owned social network is facing similar problems. “AI slop is a top priority for all of us. We really care about this. People come to LinkedIn to connect with real people and share their real perspectives, ideas, and expertise,” he said. The exec explained that the new “Seems like AI slop” button is now one of several measures LinkedIn is using to reduce the amount of low-quality, AI-generated content on its platform. The company is also investing in automation defenses, where it now blocks “hundreds of thousands” of automated comment attempts daily, and millions of other automation attempts in just the past couple of months. Srinivasan said LinkedIn is also introducing new classifiers to identify if a post is AI slop or other low-quality content, which would reduce the amount of slop you’d see in suggested content recommendations from outside your network. (The button ties into this measure as it will provide a source of signal that will allow LinkedIn to tune its AI models to better identify slop.) Plus, LinkedIn will begin privately flagging in users’ dashboards when people believe their content is coming off as inauthentic due to heavy use of AI. The company believes that this will help posters improve their writing, in the case that they’re simply using AI technology to refine their own work, rather than when they’re posting what’s considered full-on “slop” content. Notably, the company is pulling its own “enhance your post” feature that had used AI to help you write. It’s replacing it with a feature that proofreads your words, instead of changing your voice. Other improvements include expanding access to profile and page verification tools, and adding an option to block comments from company pages you no longer want to see, Srinivasan said.
View

Google says it fixed more Chrome bugs in June than over the past two years, thanks to AI
With help from its internal AI tools, Google says it has patched more security flaws in its Chrome browser in the last month than in the past two years combined. The tech giantannounced on Thursdaythat it has fixed a whopping 1,072 security bugs in the last two versions of Chrome, both released in June. That is more than the number of bugs patched in the previous 23 versions released over the last two years, which totalled 1,036 fixes. Ever since the advent of LLMs, cybersecurity experts have warned that AI-powered systems would find an increasingly and exponentially enormous amount of bugs, forcing defenders to also use AI to get ahead of malicious hackers. That prediction is starting to become true, and it’s backed by real data. A chart published by Google, which the company revealed as part of a white paper on the company’s efforts to use AI to find flaws and patch them faster, shows the exponential increase. For context, Chrome’s 126was releasedin June 2024, while the latest two Chrome releases, Chrome 149 and 150, were released last month. Google calls each version a “milestone.” Doug Turner, Chrome’s director of engineering, told TechCrunch in a statement that LLMs have “fundamentally shifted the economics of cybersecurity, transforming vulnerability discovery into an automated, industrial-scale operation.” “By applying models like Gemini, we are preemptively fixing vulnerabilities, outpacing our adversaries and making Chrome safer with every update,” said Turner. Google is not the only company seeing this trend. Earlier this month, Microsoftannouncedthat it had patched a record 570 security flaws across its product lines as part of its monthly round of scheduled patches — colloquially known as “Patch Tuesday.” Microsoft cited its own use of AI to explain the sudden jump in bug fixes. Apple, meanwhile, does not appear to be registering the same exponential increase. According toan independent countof bugs fixed by in its products, Apple has patched 482 bugs in 2026, which is roughly on pace to equal or surpass the number of fixed buts from last year, and also roughly equal from the number of bugs that Apple patched in 2015. TechCrunch reached out to Apple for comment, but did not hear back.
View

Dili raises $21.7M to bring AI compliance to the infrastructure boom
We already know that making AI work will mean bringinga lot of new data centers and power infrastructure online. But all those infrastructure projects may also need a bit of help from AI. On Thursday, a new AI compliance company calledDilithat squarely targets the new crop of U.S. infrastructure projects, said it had raised $15 million in Series A funding. The round comes on the heels of a $6.7 million seed round, bringing the company’s total capital raised to $21.7 million. The Series A was led by Khosla Ventures, with participation from Allianz, Rebel Fund, Brick and Mortar Ventures’ Darren Bechtel, and Y Combinator’s Garry Tan. Dili was previously part ofY Combinator’s Summer 2023 batch. “AI for compliance” is already a common pitch among startups, but Dili focuses on the unique tangle of rules concerning construction projects, particularly those getting some kind of federal funding. Asked for an example, Dili’s co-founder and CEO Anand Chaturvedi pointed toDavis-Bacon rules, which allow the Department of Labor to set prevailing wages for certain projects. A separate set of prevailing wage and apprenticeship rules (or PWA rules) apply to clean energy projects funded under the IRA, with various other OSHA or EPA rules in effect depending on the nature of the work. It’s a complex set of overlapping requirements, and even small mistakes can be costly. “Non-compliance can result in millions of dollars of fines for those projects,” explains Chaturvedi. “So it’s really powerful to be able to check all the information as it comes in, instead of just sampling data.” Given those high stakes, reliability is a central concern, but Chaturvedi believes Dili’s architecture will prevent any LLM-based fuzziness from sneaking into the final product. Contemporary AI models are only used in the company’s data layer, the engine for taking unstructured documents and translating them into structured data. From there, a deterministic system sorts the data according to the complex-but-static compliance rules. When it works right, a task that used to take a full day’s work can now be dispatched in a matter of minutes. “Imagine being able to read across the entire context of a company’s internal documents, all of their vendors’ documents, all of their ERP information, all of their payroll systems information, and then draw out the data that you need specifically for you know reporting or compliance,” Chaturvedi explained. Dili is already making that system work in practice. Chaturvedi says the software is already being used at “about 700 projects,” ranging from manufacturing facilities to data centers. Notably, Chaturvedi says roughly half the projects are using Dili as an in-house software tool, while the other half outsource the entire compliance process to the company on a contractor model. Dili is able to handle both types of contract, although Chaturvedi anticipates the industry will shift more towards the software model in the years to come. “Software and AI are going to start eating a lot of those professional services workflows, so I think more and more people will start to bring those in-house,” Chaturvedi says. “The interesting thing will be how the market itself evolves and where the customer needs go as AI develops.”
View

TechCrunch Disrupt 2026’s biggest stage features leaders from Amazon, Replit, Tether, with much more to come
The Disrupt Stage is where many of the biggest conversations in technology happen, with a legacy that stretches back for more than a decade. The names that have taken to the stage are so big, they are synonymous with the past era of startups and the new era of AI and major incumbents: Zuckerberg, Benioff, Musk, Kalanick, Mayer, Dorsey. And atTechCrunch Disrupt 2026, we’re tackling the biggest topic of the year with some of the biggest names to match. We’re homing in on what it actuallytakes to build, fund, and scale in the age of AI. From October 13–15 in San Francisco at Moscone Center, founders, investors, and technologists will hear directly from the people shaping the future of software, infrastructure, finance, security, and computing. Join Amazon’s Panos Panay, Replit’s Amjad Masad, Tether’s Paolo Ardoino, Flock Safety’s Garrett Langley, the full partnership at Benchmark, and more across a set of conversations built to answer the questions founders are actively grappling with right now. No prognostication. Just solutions. We’re also nearing the end of our current pricing window, so your chance to save up to $300 on a number of ticket types is ending in just a few weeks —the time to act is now! Here’s what is current on deck for the Disrupt Stage, with more announcements still to come: For nearly two decades, the smartphone has been the center of our digital lives. As AI transforms how we interact with technology, the next generation of products may look — and behave — very differently. With Panos Panay, SVP, Devices and Services, Amazon For the first time on the Disrupt Stage in San Francisco, all five Benchmark partners come together to debate where the next generation of startups will come from, what founders are getting wrong, and the opportunities still hiding in plain sight. With Benchmark partners AI is making it possible for millions of people to create software for the first time, and Replit sits at the center of that shift. A conversation about the future of programming, entrepreneurship, and what happens when anyone can turn an idea into a product. With Amjad Masad, Founder and CEO, Replit Tether processes hundreds of billions of dollars in transactions and remains one of the most debated companies in finance. A candid conversation about stablecoins, regulation, global payments, and whether crypto is finally going mainstream. With Paolo Ardoino, CEO, Tether As AI moves from the cloud into the real world, few companies sit at the center of the debate quite like Flock Safety. A conversation about privacy, security, and the trade-offs that emerge when AI becomes part of everyday infrastructure. With Garrett Langley, Founder and CEO, Flock Safety From law firms to Fortune 500 companies, AI is rapidly changing how knowledge work gets done. Harvey has emerged as one of the breakout enterprise AI companies of the last two years — a conversation about what enterprises actually want from AI, and what happens when software starts doing work once reserved for highly trained experts. With Winston Weinberg, Co-founder and CEO, Harvey AI The AI boom has created unprecedented demand for compute, energy, and infrastructure. Cerebras is challenging conventional assumptions about how AI systems should be built — and what happens if today’s hardware hits its limits. With Andrew Feldman, Founder and CEO, Cerebras For decades, humans have adapted to computers. Max Hodak believes the next era of technology will adapt to us — from brain-computer interfaces to entirely new ways of interacting with machines. With Max Hodak, Founder and CEO, Science Corp Building a breakthrough software company is hard. Building one that also designs, manufactures, and delivers world-class hardware is even harder. Rivian founder and CEO RJ Scaringe joins us to discuss what it takes to build an enduring company at the intersection of AI, software, robotics, manufacturing, and transportation. With RJ Scaringe, CEO of Rivian And this is just the Disrupt Stage. Over the full three days, you’ll also get access to our other stages: Plus, your pass unlocks access toour biggest Startup Battlefield yet, networking opportunities with many of the movers and shakers in attendance, and the exhibition floor — alongside more than 10,000 startup, tech, and VC leaders. It’s a three-day sprint in the heart of the startup community that will leave you ready for the next year of innovation —so register today!
View

In the Hugging Face breach, OpenAI’s hacker was noisy and fast — but not unstoppable
Earlier this month,AI dataset platform Hugging Face shocked the worldwhen it revealed that it had fallen victim to a fully autonomous AI-powered cyberattack. Days later, the story took another dramatic twist when OpenAI admitted that the hacker behind the breachwas one of its AI models, which broke out of a testing environment and into protected Hugging Face systems in an effort to circumvent a benchmark. It’s an alarming incident for anyone even slightly concerned about rogue AI models — and the days since the event have been full of predictions about a new cybersecurity paradigm in which AI models launch attacks so strong that only other AI models can defend against them. But despite the justified alarm, the paradigm may not have shifted quite as much as it seems. Experts who spoke to TechCrunch stressed that OpenAI’s agent largely operated like a human — with some caveats — and that better implemented traditional defensive techniques could have helped stop the attack. In short, we may already have the tools to defend against this kind of attack; we just aren’t using them properly. Hugging Face made a version of this pointin its incident report, stating that the weaknesses exploited in the attack “were familiar,” and “a capable human attacker could have found and exploited the same flaws.” Kyle Ryan, the head of R&D atPensar, a startup that develops continuous hacking AI agents, and Vlad Ionescu, the co-founder and CTO ofRunSybil, a startup that builds AI-powered bug hunters, both agreed and told TechCrunch that the techniques used in the attack would be the same ones employed by a human or a group of human red teamers. That is, hackers tasked with attacking a system to help the company that owns it improve defenses. What was very non-human-like was the speed, scale, and relentlessness of the attack.As Hugging Face explained, OpenAI’s agent performed17,600 actionsover four and a half days: It broke in, did reconnaissance, stole passwords and code, and moved around the company’s infrastructure. “What’s impressive is the autonomy and endurance,” Ryan said. “That kind of sustained, adaptive operation is what stands out most to me.” Contact UsDo you any more information about OpenAI’s hack against Hugging Face? Or other AI-powered cyberattacks? We’d love to hear from you. From a non-work device and network, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, oremail. On the flip side, given the sheer number of actions over the span of several days, OpenAI’s agent was “insanely noisy,” as Ryan put it. Unlike a human, who could have been stealthier, the agent made a lot of noise, which should have tripped up Hugging Face’s defenses sooner, ideally leading to a human intervening and stopping the attack. “I’d call it more of a defensive failure than exceptionally good offense. Hugging Face’s tooling actually correlated the activity into an attack signal, but failed to raise the criticality and page the on-call team, which cost them time,” Ryan explained. “From there, humans still had to recognize the severity and respond.” Jamieson O’Reilly, the founder of cybersecurity firmDvuln, arrived at the same conclusionin a post on Xanalyzing Hugging Face’s report. “That is the exact gap between seeing and stopping,” O’Reilly wrote. “The system observed the attack and even understood it, and nothing turned that understanding into an intervention quickly enough.” Ryan explained that properly implemented techniques such as defense-in-depth — a strategy that leverages several layers of cybersecurity measures — should have given Hugging Face multiple chances to catch the attack. “A strong modern security program should still be able to break an attack like this at multiple points through defense in depth, least privilege, segmentation, good detection, reliable escalation, and continuous offensive testing to find the gaps,” Ryan explained. As O’Reilly put it, “none of that is exotic, and none of it depends on the attacker being an AI,” given that the techniques used in the attack were “old.” What depended on the attacker being AI, in a way, was that OpenAI’s agent had not been instructed to be stealthy. “The agent was not being sloppy. It simply had no reason to be quiet. Nobody asked it to be. The objective was to do well at the task,” said Nico Waisman, the chief information security officer at XBOW, a startup that makes AI bug hunters. Waisman also pointed out that Hugging Face’s biggest mistake was that one single stolen credential gave OpenAI’s agent high privileges on several of its systems. All that being said, as the old adage goes, attackers only have to win once, and defending against hackers of any kind is not easy. “Hugging Face could’ve done more detections but to be fair not all [organizations] are doing that well,” said Vincent Yiu, managing director atSYON Security. “It’s not easy to host infrastructure and survive as a business in 2026. There’s hackers everywhere.” According to Ionescu from RunSybil, who said they have done incident responses at Mandiant and Meta in the past, Hugging Face appeared to take “reasonable measures given their understanding of what models are capable of.” “It is really hard to classify what is a malicious action you should alert on, versus what is someone just doing their job,” Vlad said. “The volume alone is not necessarily a red flag.” Dan Guido, the CEO of cybersecurity research firmTrail of Bits, told TechCrunch that OpenAI deserves some blame for not having realized the attack was ongoing for days, while Hugging Face deserves credit for eventually detecting the attack on their own. “The hard part used to be recognizing a sophisticated attack, but now the hard part may be pulling the real attack out of the noise that the attacker throws along the way,” said Guido. “Nobody is going to read 17,000 reconstructed actions by hand to work out what happened, so Hugging Face had to build tooling just to reconstruct the timeline.” And to do that, the company needed its own AI. Hugging Face said it had to use the open source model GLM 5.2 from Chinese companyZ.aiafter it was blocked from using frontier models because of their safeguards, which, as the company put it, “cannot distinguish an incident responder from an attacker.” At that point, Hugging Face combined AI and humans to investigate OpenAI’s LLM-powered hacker. That’s a relatively novel situation. But beyond that, the incident shows that old-fashioned concepts and methods of defensive cybersecurity can still go a long way to protect and fight against AI hackers.
View

Forward-deployed engineers are the AI industry’s latest talent obsession
Executive search firm Christian & Timbers estimates that there are only about 2,000 engineers in the U.S. with the special cocktail of sector know-how, gravitas, and hands-on applied AI experience needed to consistently help enterprises see a return on their AI expenditures. “Not 2,000 available,” reads the study, shared exclusively with TechCrunch. “2,000 total.” As enterprises move from trying to access the best models to figuring out how to implement them into workflows that meaningfully improves their bottom line, it appears the forward-deployed engineer (FDE) — engineers who work within client organizations to build, implement and deploy software or AI models — is about to become among the most sought-after specialist in the AI industry. Demand for FDEs is already rising rapidly, according to the C&T study, which projects demand for these specialists to surge by 2,100% by the end of the year. The research draws on interviews with more than 250 C-suite hiring executives across 180 companies, a focused survey of 80 Fortune 500 executives, and interviews with more than 300 FDEs and applied AI engineers between January and June 2026. At the start of the year, only 5% to 10% of companies were planning to hire FDEs, and mostly only for small pilots. By the end of the second quarter, however, that number jumped to 70%, with the largest consulting and services firms reporting a need to increase their FDE headcount by 10 times, building full teams of 20 to 100 employees. “This is all happening at a speed I’ve never seen. Enterprises are hiring in the middle of summer,” Jeff Christian, founder of C&T told TechCrunch. That kind of demand will outstrip supply, if C&T’s study is accurate. The report found that there are roughly 17,000 U.S. FDEs on the market today, a good chunk of whom are already employed by Palantir, which invented the concept of the FDE years ago. (Christian said some of his clients are even buying Palantir’s technology just so they can access the firm’s FDEs.) Only a fraction of the FDEs out in the wild are apparently elite enough to deliver true ROI, which these days is measured as “multiple tens of millions of dollars of ROI impact,” according to Christian. That could manifest as revenue acceleration on the go-to-market side (lead generation) or “replacing FP&A or replacing 2,300 document processors in India,” Christian says. As Chris Taylor, CEO ofOde with Anthropic(a new FDE-focused services firm), put it: “Many FDEs are well equipped to help you roll Claude Code out to your workforce. Very few are capable of building your flagship AI product feature.” Now that token-maxxing has morphed into value-maxxing, andenterprises taking a harder lookat their balance sheets, accounting for AI spending is becoming more important than ever. “This fall, [Wall Street] is about to say, ‘Hey, we’ve given you two years to figure this out…and you haven’t. There’s no ROI. So we’re going to start punishing those that have spent hundreds of millions, maybe even billions on this, and aren’t generating ROI, and rewarding those that have’,” Christian said. Loading the player… AI companies are under pressure, too, as they’ve already spent tens of billions to train and deploy their models. For frontier AI firms, reaching profitability will depend on whether they can inject their technology into as many enterprises as possible, though that task is now being threatened by cheaper, increasingly capable open-weight models from China. That’s why firms likeOpenAI and Anthropichave set up their own ventures —Ode with Anthropicand OpenAI’sDeployment Company— and staffed them with FDEs whose sole purpose is to go forth and spread their tech around the enterprise. It’s not only top AI firms and large consultancies clamoring for FDEs, however. Enterprises from insurance and fintech to healthcare and gaming, are seeking out these specialists, Christian said. Companies are hiring teams of FDEs instead of bringing them in from firms like Ode, or Deployment Co, seeking to keep knowledge of proprietary processes in-house and protect them from the likes of OpenAI and Anthropic. “Everybody’s concerned that if they give up their proprietary business processes, [the AI firms] can compete with them, which is true in many different areas,” Christian said. “So having this muscle internally is so important.” Taylor said he’s starting to hear the phrase “internal forward-deployed engineers” more often, but his clients aren’t yet asking Ode to put together internal FDE teams for them. While many an enterprising young engineer might think they have the industry expertise and AI chops to take advantage of what may turn out to be a talent war, Christian warns that the FDE may not always be in demand. “Maybe in two years, everything’s automated, and agents are automating agents as opposed to humans automating agents,” Christian said. “That is something that could occur. Hopefully, it doesn’t, and we continue to need these people within companies.” In the medium-term, he thinks the need for FDEs will shift from enterprise AI to physical AI as companies try to implement things like humanoid robots into their workflows. But within five or 10 years, he says it’s entirely possible that the role of FDE will “go away.” That may be true for all knowledge work, if AI leaders and CEOs’ vehement predictions come true. While C&T focuses on recruiting for fast-growing industries and hasn’t seen a pullback yet, Christian says more general search firms have definitely experienced a slowdown in recruitment requests. Everything to do with AI is growing and in demand, he says. For now. “I think that there’s absolutely a time soon where we’re going to see an impact in our business,” Christian said.
View

Nscale buys Anyscale as it seeks to own more of the AI compute stack
In a bid to capture more of its customers’ AI spending, British AI neocloudNscaleis buying software startupAnyscale, which helps companies scale their AI workloads across data centers and servers. Nscale is paying $1.65 billion for Anyscale, Bloombergreported, citing an anonymous source. Founded by the same team that built the open-sourceProject Raydistributed programming Python framework, Anyscale started by building a platform that allowed people to run projects that needed large amounts of computing power. But after the launch of GPT-3 in 2022 brought AI into the spotlight, the company pivoted to offer scaling services for serving and training large language models, data curation, inferencing, reinforcement learning, and other tasks. The company’s platform is built around Ray, offering developer tools, observability and orchestration. A deal to buy Anyscale would fall neatly into Nscale’s focus on building vertically to serve compute needs. The neocloud has set up business lines across energy, data centers, orchestration software, and now, with Anyscale, it will also offer workload management and scaling. “Together, Anyscale and Nscale can co-design the software layer and infrastructure beneath it, something that neither company could do as effectively by optimizing its layer alone,” Anyscale said in astatement. Nscale this March raised$2 billionin a Series C round that saw it valued at $14.6 billion. Its investors include Nvidia, Nokia, Blue Owl, Dell, and Norwegian industrial giant Aker. The neocloud has been busy putting that money, as well asvariousdebtraises, to work, securing compute and data center partnerships with the likes ofMicrosoft,British Telecom, andNordcraft. Anyscale, which was valued at $1.38 billion in a 2022Series C round, said its revenue increased by 70% in its most recent quarter, compared to the previous sequential quarter. Nscale said Anyscale will continue to operate under its own branding and serve its existing customers. The startup’s about 200 employees are all joining Nscale.
View
