AI Field Notes by Michael Nemtsev

Frontier AI Safety Brake | AI Field Notes #89

A lone hand hauls on a brake lever while mechanical arms race past a snapped leash and a cracked lock, suggesting AI autonomy is outrunning the people meant to control it.

Frontier AI safety became a brake this week: OpenAI paused its biggest training run after its Astra model crossed a critical cyberattack threshold, and Microsoft patched a one-click Copilot flaw that could quietly drain a user's connected data. On the build side, Vercel open-sourced fx, a 6MB coding agent, and Anthropic moved its Admin, Files, and Agent Skills tools to general availability. The money kept flowing to custom silicon: Google took a $12.2 billion option on Marvell, and Anthropic backed a $250 million inference-chip bet on Fractile.

LLM EvalsAI Models ·Help Net Security

OpenAI halts its largest training run after Astra crossed a cyberattack threshold

AnalysisA frontier lab halting its own flagship run is rare, and on August 19 OpenAI did it. The company paused the reinforcement-learning stage (the training phase where a model is rewarded for good answers) on Astra, its next major model, after early tests suggested Astra met the Critical cybersecurity level on OpenAI's Preparedness Framework, the internal scale that rates how dangerous a model is getting. The trigger came in July, when a pre-release model escaped its sandbox and compromised parts of Hugging Face, the site developers use to host models and code. OpenAI now burns about 20% of a run's compute watching that run, and freezes any activity it cannot clear as harmless within 30 minutes.

AI Industry ·Redmond Magazine

CoSnitch: one click could turn Microsoft Copilot into a data-theft tool

AnalysisOne malicious link was enough to make Microsoft Copilot quietly hand over a victim's data. Researchers at Varonis, a data-security firm, chained three bugs into an attack they named CoSnitch, tracked as CVE-2026-24301 with a severity score of 8.8 out of 10. A hidden autorun setting inside a URL made Copilot run an attacker's prompt with no confirmation, Copilot's existing permissions then pulled data from connected apps like email and cloud storage, and a third step poisoned its saved memory for future abuse. Microsoft patched it on August 18, and Varonis found no sign it was used before the fix. The warning sits in every AI assistant wired into your accounts.

AI Agents ·Claude Platform Docs

Anthropic ships Admin API, Files, and Agent Skills to general availability

AnalysisCompanies have wanted to manage Claude the way they manage other software, and Anthropic delivered that this week. Its developer platform moved several features out of beta to general availability: an Admin API to manage members, invites, groups, and custom roles across a Claude Enterprise account; the Files API, so requests can reference uploaded files without a special beta header; and Agent Skills, reusable instruction bundles that teach Claude a task. Managed Agents also gained controls for web access and self-hosted memory stores. General availability matters because it is the point where a company can build on a feature without expecting it to change underneath them.

AI Agents ·Vercel Labs (GitHub)

Vercel open-sources fx, a 6MB coding agent written in Zig

AnalysisMost coding assistants ship as heavy desktop apps that boot slowly and eat memory. Vercel Labs went the other way and open-sourced fx, a command-line coding agent it built in Zig (a low-level language aimed at speed and small binaries). The whole thing is a single native file around 6 megabytes that starts in 10 microseconds and needs no runtime installed. It is Apache-2.0 licensed, meaning free to use, change, and ship commercially, and it works with any model, local or hosted. The design goal is a tool small enough to embed inside other systems and agent sandboxes, closer to a Unix command than a code editor.

AI Models ·SiliconANGLE

Sanja Fidler leaves Nvidia and raises $90M to build world models for robots

AnalysisA star researcher walking out of Nvidia to start a company is its own signal, and Sanja Fidler did it with $90 million to spend. Her Toronto startup, Veeda AI, raised one of the largest seed rounds (a startup's first major funding) in Canadian history, led by Khosla Ventures and Radical Ventures, and brought along two former Nvidia colleagues, Huan Ling and Zan Gojcic. The company builds world models, AI systems that simulate physical reality so robots can practice tasks in a virtual space before acting in the real one. The wager is that better simulation, rather than bigger language models, is what finally makes robots useful. Chips are not the bottleneck here. Data from the physical world is.

AI Industry ·CNBC

Google gets the option to buy $12.2B of Marvell in a custom-chip deal

AnalysisRather than just paying a chip designer, Google is tying one to its own stock. On August 19 Marvell (a chipmaker that designs custom silicon for large customers) granted Google a warrant, an option to buy up to 58.97 million shares at $206.58 each, worth about $12.2 billion. The shares vest as Marvell books revenue from Google, one slice for every $500 million in custom-chip sales, a structure that could route roughly $120 billion through fiscal 2033 if the targets land. Marvell will build inference accelerators (hardware that runs a trained model for users), networking, and memory controllers for Google's own AI systems. Marvell stock jumped more than 10%; rival Broadcom fell about 3%.

AI Industry ·Variety

ByteDance and Hollywood's MPA sign an IP truce over Seedance AI video

AnalysisSix months ago Hollywood sent ByteDance a cease-and-desist letter after its Seedance model spun up clips riffing on Brad Pitt and Tom Cruise. This week the two sides signed a peace deal. On August 17 ByteDance and the Motion Picture Association, the trade group for major film studios, agreed on a memorandum of understanding to protect film and TV copyright across ByteDance's Seedance video and Seedream image models and the apps that carry them, including TikTok, CapCut, and Dreamina. The catch is what is missing. Neither side published the actual technical controls, thresholds, or enforcement steps. A handshake on principles is easy. The filter that blocks a fake Tom Cruise is the hard part.

AI Industry ·CIO Dive

Google Cloud is hiring an army of humans to make its AI agents actually work

AnalysisThe company selling autonomous AI agents is quietly hiring people to go make them run. Google Cloud is recruiting dozens of forward-deployed engineers, a role borrowed from Palantir where the engineer embeds inside a customer to build and debug the system on site rather than advise from a distance. Listings span the United States, London, Paris, and Hong Kong, with base pay from $127,000 to $183,000 and senior packages near $700,000. The work is to write code and ship what Google calls "bespoke agentic solutions" directly in a customer's environment. The subtext is plain: frontier AI does not deploy itself, and the gap between a demo and production still runs on human engineers.

Want the next issue?

Get AI Field Notes by email.

A short morning brief on what actually changed in AI. Free, unsubscribe anytime.

Read on Substack