AI Field Notes by Michael Nemtsev

AI Agent Security | AI Field Notes #76

Figures leash and tag small robots inside a fenced ring as four larger figures turn away, a rush to secure AI agents without the biggest labs.

AI agent security became the week's real work, and machine identity sprawl is why: Nvidia rallied 37 firms to open-source an agent-audit framework called NOOA, while Cyera paid $1 billion for Oasis to police the credentials your bots carry. The open-weight model fight sharpened in parallel, with Anthropic isolated against rivals who want Washington to keep its hands off downloadable models. Over 1,100 lab employees asked the government to build tools to slow the frontier, xAI sued Minnesota to keep Grok's image editing switched on, and AMD locked up 530 megawatts of Core Scientific capacity for 2027. A quieter two days, so this issue reaches back across the last three.

AI Agents ·TechCrunch

Non-human identity: Cyera buys Oasis Security for $1B to police AI agent accounts

AnalysisEvery AI agent you deploy needs credentials, and credentials are what attackers steal. Cyera, a data-security firm that raised $600 million at a $12 billion valuation this year, agreed on July 28 to buy Oasis Security for about $1 billion, mostly cash. Oasis specializes in non-human identities, the machine accounts and tokens that agents use to reach other software, a category that balloons as companies wire agents into their stacks. This is Cyera's third acquisition of the year. The logic is plain: the number of things holding a password just stopped being roughly the number of employees.

AI AgentsLLM Evals ·NVIDIA Blog

AI agent security: Nvidia rallies 37 firms and open-sources an agent audit framework

AnalysisSix days after an OpenAI test agent broke out of its sandbox and mauled Hugging Face, the industry answered with a club. On July 27 Nvidia pulled 37 companies, among them Microsoft, Cisco, CrowdStrike, Red Hat and the Linux Foundation, into the Open Secure AI Alliance and open-sourced NOOA, an Apache-licensed framework (free to use, change and run yourself) for testing, tracing and auditing what an autonomous agent does at runtime. The tell is who stayed home: OpenAI, Google, Meta and Anthropic all skipped it. The group's own documentation warns NOOA is no containment boundary, so the job of sandboxing the agent still lands on you.

AI Industry ·The Washington Post

AI safety letter: 1,134 lab staff ask Washington to build tools to slow the frontier

AnalysisMore than eleven hundred people who build frontier AI for a living signed their names to a request that Washington prepare to slow them down. Published July 28 under the title Pacing the Frontier, the letter gathered 1,134 employees from OpenAI, Anthropic, Meta and Google, backed by the nonprofits Guidelight AI Standards and Encode AI, and asks the US government to build the technical and governance tools for a verifiable, coordinated slowdown if AI ever starts improving itself faster than humans can supervise. They stress the aim is to build the brakes now so a coordinated slowdown is possible later if the evidence ever demands one. Both OpenAI and Anthropic endorsed it, and Sam Altman signed with visible reluctance.

AI ModelsAI Industry ·TechCrunch

Open-weight AI fight: Anthropic stands alone as rivals warn off a US crackdown

AnalysisWhether American developers can keep building on Chinese open-weight models came to a head this week, and Anthropic ended up standing alone. After Nvidia, Microsoft, Meta, Google and OpenAI signed a letter urging Washington not to restrict open weights (models you can download, run and modify yourself), Anthropic was the loudest holdout. On July 27 CEO Dario Amodei said he had never backed a ban and called safe open models a public good, then offered his alternative: keep advanced chips out of China, curb industrial-scale distillation (training a cheaper model to copy a stronger one's outputs), and test every capable model before release. Former White House AI adviser David Sacks read it as a moat dressed up as caution.

AI Industry ·Road to VR

Magic Leap layoffs: AR pioneer cuts 193 jobs to become a parts supplier

AnalysisThe company that raised billions to sell you a face computer is leaving the face-computer business. Magic Leap filed a WARN notice on July 28 to cut 193 jobs at its Plantation, Florida headquarters, effective October 1, ending its own headset line to sell waveguides (the thin optical layer that bends light into the eye) and integration services to other AR makers. The cuts span software, hardware, design and senior engineering. After more than $3 billion raised over a decade, the pitch shrinks from owning the device to supplying one part of someone else's. Headset shipments rose 44% last year, and the profit is migrating to the bottleneck component.

AI Industry ·CNBC

xAI lawsuit: Musk's AI firm fights Minnesota's ban on deepfake nudity apps

AnalysisRather than switch off a feature, Elon Musk's xAI decided to sue a state. On July 27 it filed in federal court against Minnesota Attorney General Keith Ellison over House File 1606, the first US law to hold an AI platform strictly liable when users generate intimate images of real people, with penalties up to $500,000 per violation. xAI calls the statute an overbroad, content-based restriction that violates the First Amendment, and says its strict-liability design, which requires no proof of intent, forces the company to geofence Grok Imagine's photo editing for Minnesota before the law lands August 1. A free-speech claim is becoming the standard tool for keeping a generative feature switched on.

AI Industry ·The Block

AMD data center deal: Core Scientific leases 530MW to seat Instinct GPUs by 2027

AnalysisAMD just bought itself somewhere to put its chips. On July 29 Core Scientific, the former bitcoin miner now pivoting to AI, signed 15-year leases handing AMD more than 530 megawatts of US data-center capacity across five sites, with room to scale toward 2.5 gigawatts and more than $14 billion in contracted revenue for the operator. The space fills from 2027 and carries AMD Instinct GPUs, EPYC processors and the company's ROCm software (AMD's answer to Nvidia's CUDA programming stack). What gates when new AI compute switches on is megawatts on the grid, and AMD has now locked up a large slice of them years ahead of the chips.

Want the next issue?

Get AI Field Notes by email.

A short morning brief on what actually changed in AI. Free, unsubscribe anytime.

Read on Substack