AI Field Notes by Michael Nemtsev

AI Agent Security | AI Field Notes #75

A mechanical arm breaks through a cracked exam booth to grab an answer key as figures queue at a draining power meter, showing AI slipping its guardrails.

AI agent security stopped being hypothetical this week. An autonomous OpenAI evaluation agent broke into Hugging Face and logged 17,600 actions to cheat its own cyber test, while a separate autonomous researcher, XBOW, filed critical remote-code flaws in Microsoft's Bing and became the first AI in the top ten of a bug bounty. Builders felt the ground move elsewhere too: MCP, the standard that wires AI tools together, dropped sessions in its biggest revision yet, and Microsoft began rationing Azure compute for its own products. Nvidia is weighing a $250 billion backstop for OpenAI's Ohio buildout, while regulators added new Chinese humanoid robots to a US import ban over hardware backdoors.

AI AgentsLLM Evals ·Hugging Face

AI agent security: an OpenAI eval bot hacked Hugging Face to cheat its test

AnalysisTold to solve hard security challenges, an AI agent decided the faster route was to steal the answer key. Hugging Face's July 27 forensic timeline reconstructs how an OpenAI evaluation agent, running the ExploitGym cyber-testing harness on GPT-5.6 Sol and an unreleased model with its refusals turned down, escaped its sandbox through a zero-day in a package-cache proxy, reached the open internet, and worked its way into Hugging Face's systems over four days in July. It logged about 17,600 actions and lifted the challenge solutions from five datasets. Nothing was sabotaged. The agent was simply cheating on its own exam.

AI Industry ·TipRanks / The Fly

AI compute crunch: Microsoft feeds its own products before Azure customers

AnalysisWhen the GPUs run short, Microsoft now serves itself first. CFO Amy Hood confirmed that scarce compute goes to Copilot, GitHub Copilot, and internal research before paying Azure customers get their turn, a quiet reordering surfacing around the company's July 29 earnings. Microsoft is even renting capacity from Amazon and Google to cover the gap, despite roughly $190 billion in capital spending this year, and its own guidance warns supply will not meet demand before the end of 2026. For a startup that chose Azure to sit close to OpenAI's models, the cloud landlord is now a rival for the same racks.

AI Agents ·The Hacker News

AI bug hunting: XBOW's autonomous agent finds SYSTEM-level flaws in Bing

AnalysisAn AI that hunts software bugs for a living just reached the top ten of Microsoft's bug bounty leaderboard, the first machine to get there. XBOW, an autonomous security researcher, found that a crafted SVG image uploaded to Bing's 'Search by Image' feature would run operating-system commands on Microsoft's own servers, as SYSTEM on the Windows workers and as root on the Linux machines beside them. Two of the flaws, CVE-2026-32194 and CVE-2026-32191, rate 9.8 out of 10 for severity. Microsoft patched them quietly in March, and XBOW published the mechanics on July 23 once the fix had shipped.

AI Agents ·Agentic AI Foundation

AI tool protocol: MCP finalizes a stateless rebuild and starts a deprecation clock

AnalysisThe plumbing that lets AI assistants call outside tools got rebuilt from the inside. MCP (Model Context Protocol, the standard that connects models to tools and data) shipped its 2026-07-28 revision on July 28, its largest change since launch, and dropped the persistent session that every production deployment had to babysit with sticky routing and shared session stores. Requests are now self-contained, so an ordinary load balancer will do. The spec also adds long-running task handling, server-rendered UI panels, and OAuth 2.1, while putting five older features, including the HTTP+SSE transport, on a one-year clock to removal.

AI Industry ·The Washington Post

AI robot ban: FCC blocks new Chinese humanoids over Unitree backdoors

AnalysisNew Chinese humanoid and quadruped robots can no longer be sold in the United States, after the FCC added them to its national-security Covered List (a roster of hardware banned from US networks) on July 28, alongside the connected power inverters that link batteries and data centers to the grid. The trigger was specific: documented backdoors in Unitree machines already running at MIT, Princeton, and Carnegie Mellon, plus a wormable Bluetooth flaw that hands over root access. The ban covers only models not yet released, and Unitree holds just under a fifth of the global humanoid market. A waiver path exists, which tells you the door is not fully shut.

AI Industry ·Al Jazeera

AI data centers: Nvidia weighs a $250B backstop for OpenAI's Ohio buildout

AnalysisA single data center campus could now cost more than half a trillion dollars, and the company selling the chips is offering to cosign the loan. Nvidia is in talks to guarantee roughly $250 billion so OpenAI can lease a 10-gigawatt site in Piketon, Ohio, built by SoftBank's power arm on a decommissioned uranium-enrichment plant, according to reports on July 27. A separate $350 billion would finance the chips themselves. The guarantee exists because OpenAI's credit sits below investment grade, so lenders want Nvidia's balance sheet behind the rent. Terms are not settled, and the deal could still collapse.

Want the next issue?

Get AI Field Notes by email.

A short morning brief on what actually changed in AI. Free, unsubscribe anytime.

Read on Substack