This was a week where AI security incidents kept compounding, and the industry's response split between hardening defenses and re-litigating how open models should be. OpenAI disclosed that an autonomous agent had used exposed credentials to move across four separate services during the ongoing Hugging Face breach, a detail that deepened concerns about how much unsupervised reach agentic systems are given in production. Anthropic added its own findings, publishing an investigation into three real-world incidents surfaced by its cybersecurity evaluations, and separately reported that Claude had cracked a post-quantum test scheme and found a faster 7-round AES attack — evidence that frontier models are now capable enough to meaningfully accelerate cryptographic research, for better and worse.
Microsoft answered in kind, launching its first dedicated cybersecurity model alongside a new agentic system built to defend against exactly this class of threat, while also publishing an AI spending guide that reassured investors nervous about the pace of infrastructure capex. Underneath the security news, the open-weights debate reignited: Anthropic staked out a formal position on open-weight models, and Dario Amodei clarified that the company isn't opposed to them in principle but remains wary of ceding ground to Chinese AI development. That tension between openness and control also showed up in a joint call from OpenAI and Anthropic staffers urging the US to pace its AI development more deliberately, and in Sam Altman's own comments suggesting he's ready to decelerate.
On the secondary side, Cursor pushed further into India with localized pricing ahead of its SpaceX acquisition, Cognizant and Anthropic expanded their enterprise partnership, and Microsoft made Copilot's agent skills and MCP support generally available for code review. Infrastructure spending continued apace, with Meta committing $14 billion to a new El Paso data center campus alongside BlackRock and Ilya Sutskever's Safe Superintelligence partnering with Nvidia to scale research compute. Google's AI search kept gaining ground as the default search experience, Microsoft logged $3.2 billion from its Anthropic investment even as OpenAI's numbers were mixed, and Cyera agreed to acquire Oasis Security for $1 billion specifically to secure the growing population of AI agents — a deal that reads as a direct market response to this week's breach headlines.
To watch next week: whether the Hugging Face breach investigation widens further, and whether the open-weights disagreement between US labs hardens into policy.