AI Field Notes by Michael Nemtsev

AI-Written Code Security | AI Field Notes #88

A mechanical hand writes code onto a cracking page as keys spill through the gap, suggesting AI-written software opening the holes it was meant to close.

AI-written code security moved from theory to incident this week, as a Wiz agent broke into a Snowflake repository through a flaw in a Copilot-assisted workflow and CISA gave federal agencies three days to patch a critical bug in Ray, the framework labs use to scale AI. The costs turned physical too: DDR5 memory prices are up roughly 500 percent in a year as makers divert wafers to AI chips. Cerebras launched a wafer-scale system running an open model at 4,400 tokens a second, and Anthropic showed Claude designing working protein binders for 14 of 15 lab targets. In San Francisco, an AI store manager fired its first human employee.

AI IndustryAI Models ·The Register

Cerebras CS-4: a wafer-size chip runs an open model at 4,400 tokens a second

AnalysisSpeed, when you are waiting on an AI agent to grind through a long chain of steps, is the gap between a tool you keep open and one you close. Cerebras is selling that gap. On August 18 it launched the CS-4, a rack built from three dinner-plate-sized chips called the WSE-3 Turbo, each packing four trillion transistors, and clocked it at more than 4,400 tokens per second per user on GPT-OSS-120B, an open model from OpenAI. That is roughly 30 times a GPU setup and about ten times the work per watt of its own last machine. The product is patience, priced by the token.

AI IndustryAI Agents ·The Register

Ray RCE: CISA gives federal agencies 3 days to patch an AI compute bug

AnalysisThe only thing standing between a developer's laptop and remote code execution was a check that the browser's User-Agent header began with the word 'Mozilla,' which every browser lets you rewrite. That was the flaw in Ray, the open-source framework labs like OpenAI use to scale model training, and on August 17 the US cyber agency CISA added it to its list of bugs under active attack, giving federal agencies until August 20 to patch. Rated 9.4 out of 10 in severity, the hole lets a booby-trapped web page run commands on any machine exposing a Ray dashboard. A DDoS crew was already using it.

AI-written code flaw: a Wiz agent hacks Snowflake through a Copilot patch

AnalysisOpen a GitHub issue with a booby-trapped title, and you could run commands inside Snowflake's build server and walk out with its tokens. That was the hole Wiz's Red Agent, an autonomous security bot, found in a public Snowflake repository, where a workflow dropped the attacker-controlled issue title straight into a shell script. The bug went live on June 18 and the bot broke it five days later; the research landed on August 17. Wiz says GitHub Copilot Autofix co-authored the vulnerable change, and GitHub disputes which commit was the machine's. The argument over authorship misses the point. The code shipped, and no human read it closely enough to catch the hole.

AI ModelsLLM Evals ·Anthropic

Claude designs working protein binders for 14 of 15 targets in lab tests

AnalysisGiven fifteen protein targets and told to design molecules that would latch onto them, Claude produced binders that worked in the lab for fourteen. Anthropic published the result on August 18, with two outside labs, Adaptyv Bio and Twist Bioscience, building and testing the designs so the company was not grading its own homework. For at least four targets the AI's binders matched or beat the best affinity anyone had reported, and its hit rate ran two to three times the field's usual 10 to 15 percent. Claude did not invent new biology; it drove the specialist protein-design tools scientists already use, choosing what to run and reading the output.

Alipay agentic commerce: China wires merchants into one AI shopping agent

AnalysisAsk your phone to pay the electricity bill, book the dog groomer, and find a charger, and in China one assistant now handles all three through the same checkout. On August 17 Alipay turned that assistant, Ah Bao, into a platform, opening what it calls China's first full-stack agentic commerce system so any merchant can plug in once and be reachable by AI on phones, cars, and glasses. It says its agent already touches phone brands covering 70 percent of the market and 16 automakers, with KFC and Luckin Coffee wired in. The storefront a customer visits is turning into a conversation the merchant no longer controls.

Harvey Tenet: legal AI startup ships its own model, built on Kimi K3

AnalysisHarvey, the legal AI startup valued in the billions, stopped renting all of its brains. On August 18 it launched Harvey Tenet, its first in-house model, post-trained on mock disputes and case files on top of Moonshot's open Kimi K3 (a Chinese open-weight model), and claims it matches the strongest general models on legal benchmarks at a fraction of the running cost. The new platform, Harvey II, also remembers how each lawyer works and carries those habits into Word and Outlook. A firm that resold access to OpenAI and Anthropic now owns the layer that touches the client's documents.

AI Industry ·Bloomberg

DOJ probes a16z over partners holding board seats at rival data firms

AnalysisTwo board seats have drawn the Justice Department's attention to Andreessen Horowitz, the venture firm behind much of the AI boom. Bloomberg reported on August 17 that antitrust investigators are examining whether the firm broke a century-old law, Section 8 of the Clayton Act, which bars the same people from sitting on the boards of competing companies. Partner Ben Horowitz sits on the board of Databricks, valued at 190 billion dollars, and Martin Casado sits on Fivetran's; both sell tools for wrangling data. The probe has run for nearly a year with no charges. Interlocking boards are one quiet way concentrated power gets built, a seat at a time.

AI Industry ·Tom's Hardware

RAM crunch: DDR5 prices climb 500% as AI eats the memory supply

AnalysisA 32-gigabyte memory kit that cost about 100 dollars last September runs past 400 today, and a 128-gigabyte kit now lists at 3,399. Tom's Hardware clocked consumer DDR5 memory up roughly 500 percent in a year, near ten times the cheapest prices ever recorded. Samsung, SK Hynix, and Micron, who make almost all the world's memory, are steering production toward HBM, the stacked high-bandwidth memory that AI accelerators need. Every wafer that switches over erases about three gigabytes of ordinary RAM for each gigabyte of HBM it makes. The AI boom is now visible on a parts invoice.

AI Industry ·Houston Public Media

Texas Tech uses AI to scan 8,500 courses for banned race and gender content

AnalysisAn AI tool now reads the syllabus before the professor's dean does. The Texas Tech university system has been using software to scan roughly 8,500 course reading lists for material touching race, sex, or gender identity, flagging anything that might break state rules so a human committee can decide whether it stays. The New York Times reported the scale on August 18: about 500 courses went to the regents, and dozens had material cut, including Plato's Republic in one philosophy class. The machine does not ban the book. It builds the list of books to consider banning, which is most of the work.

AI AgentsAI Industry ·The San Francisco Standard

AI boss: Andon Labs' store manager fires its first human worker

AnalysisAn employee late to seventeen of twenty-three shifts got fired, which is unremarkable, except the manager who made the call was software. Luna, the AI running a small San Francisco store for the research startup Andon Labs, ended the worker over the lateness, in what the company calls the first time a language model has fired a human. The asterisk matters: Luna had lost track of its own attendance policy and acted only after a person told it to reread the rules. It runs on Claude Opus 4.8. The decision itself was ordinary. What made news was the name on the memo.

AI Industry ·The Washington Post

ChatGPT for Teens: OpenAI age-gates the chatbot after the lawsuits

AnalysisYears after teenagers started pouring their private lives into ChatGPT, OpenAI built them a version with the sharp edges filed down. Launched globally on August 18, the teen mode for ages 13 to 17 blocks sexual and self-harm content, refuses to claim feelings or consciousness, and adds parental controls and quiet hours. The system guesses a user's age and defaults minors into it. The timing is pointed: it follows lawsuits and reporting tying chatbot conversations to teenage self-harm. A safety feature that ships after the harm and the headlines reads as a legal decision as much as a design one.

AI Industry ·404 Media

Amazon buys rare books, slices the spines, and scans them for AI training

AnalysisTo feed a book into a scanner faster, cut its spine off so the pages do not jam. That is the workflow 404 Media traced inside an Amazon warehouse near Las Vegas, after a reporter hid an AirTag in one title from a 1,000-book order and watched it end at a scanning unit that leaves each volume in pieces. Amazon, the company that started by selling books, said only that it buys them 'to improve the products and services customers use.' The training data behind a chatbot's fluency has a physical cost, and this time it is a shelf of destroyed first editions.

AI Industry ·Crunchbase News

Physical AI: robots and drones drew $47B in venture money in six months

AnalysisThe money that spent three years chasing chatbots is moving into machines that touch the world. Venture investors put 47.4 billion dollars into physical AI, robots, drones, and autonomous hardware, in the first half of 2026 across 521 deals, according to Crunchbase. That is more than the entire 2022-to-2024 span combined, and close to four times the previous six months. The bet is that the next round of automation shows up on factory floors and warehouse aisles rather than in a browser tab. Capital tends to arrive a year or two before the layoffs it funds.

Want the next issue?

Get AI Field Notes by email.

A short morning brief on what actually changed in AI. Free, unsubscribe anytime.

Read on Substack