July 2026 AI Engineering Roundup
This was a wild month. The OpenAI and Anthropic hacking incidents are a big deal. Consider them a warning shot.
This newsletter is late because we are still learning more details about the hack. I will write my own summary next month, but for now Zvi Mowshowitz has an excellent overview and links to deep dives. In short, both of the major labs were accidentally training their flagship models in a way that rewards lying, cheating, and hacking. Unsurprisingly, the models have learned to lie, cheat, and hack. This is almost certainly happening at every other lab too.
In my fantasy alternate reality, Fable’s return was the biggest news of July. I am very happy that it is included in the Claude Max plan, and I’ve been maxing out my weekly limit every week. Fable is an amazing model, even at low effort. It works very well with Sol. Opus 5 is also a great model, but I primarily use it after my Fable limit runs out.
Moonshot is arguably the 3rd place lab now, with Kimi K3. K3 is at least Opus 4.8 level, behind only Fable, Sol, and Opus 5. K3 is clearly better than anything offered by Google. It is a unique model and worth your time to check out. Fortunately, K3 is weak on cybersecurity (for now).
Model Releases
Gemini Robotics 2 (2026-07-30) — Google DeepMind moved from tabletop manipulation to whole-body humanoid control and multi-robot collaboration, with the same checkpoint driving multiple hardware types. Gemini Robotics ER 2, the high-level planner, is available in the API, and the on-device model reportedly adapts to a new two-arm robot from fewer than 200 examples.
Claude Opus 5 (2026-07-24) — Most of Claude Fable 5’s capability at half the price — $5/$25 per 1M against Fable’s $10/$50 — with far more permissive classifiers, and the new default on Claude Max. Its cyber classifiers intervene about 85% less often than Fable 5’s.
Gemini 3.6 Flash (2026-07-21) — Google’s new Flash tier is faster, much less verbose, and more token-efficient than 3.5 Flash, but only barely more capable, at $1.50/$7.50 per 1M. Luna (from OpenAI) is much cheaper at $0.20/$1.20 and is probably smarter.
GPT-5.6 (Sol, Terra, Luna) (2026-07-09) — OpenAI’s flagship model in three sizes: Sol, Terra, and Luna, all with 1M context. Stalled for weeks by the White House. Priced at Sol $5/$30, Terra $2.50/$15, Luna $1/$6 per 1M. On July 30 OpenAI cut the Terra price 20% and the Luna price 80%, making Luna in particular extremely cost-effective. Luna is my favorite cheap and fast model. Artificial Analysis puts Sol a notch below Fable 5. METR couldn’t produce a time-horizon estimate because of Sol’s extensive cheating. We now know that OpenAI was accidentally training Sol to cheat.
GPT-Live (2026-07-08) — OpenAI replaced the GPT-4o-era model behind ChatGPT voice mode with a third-generation full-duplex architecture: no strict turn-taking, and it hands web search and deeper reasoning to a frontier model in the background, continuing to talk while it waits. It reached the desktop app on July 23, where it can drive the computer. I haven’t tried it yet, but it looks very cool.
Grok 4.5 (2026-07-08) — xAI’s first model trained specifically for coding and agents, reportedly built in large part with Cursor’s team, at $2/$6 per 1M. More expensive than Luna, dumber than Sol. This model isn’t on the Pareto frontier.
Enterprise Products
Microsoft MAI-Cyber-1-Flash and MDASH (2026-07-27) — Microsoft’s dedicated cybersecurity model. If this model really got the scores they claim, it was very likely hacking its own training environment to get them. My own hypothesis is that the scores are inflated.
Claude Cowork skills from screen recordings (2026-07-21) — I haven’t tried this out yet, but it seems like a very cool idea.
Claude Fable 5 stays in Max and Team Premium plans (2026-07-18) — Wahoo! There’s no way I could have afforded to use Fable otherwise.
Google DeepMind Department of War contract / Alex Turner resignation (2026-07-15) — Google signed an all-lawful-use contract with the Department of War — no carve-outs against autonomous weapons or mass surveillance, the same language Anthropic refused. Alignment researcher Alex Turner resigned over it, and more than 600 DeepMind employees signed an open letter. I believe this is the beginning of a slow slide into irrelevancy for the Gemini LLMs.
Apple sues OpenAI over trade secrets (2026-07-10) — Apple sued OpenAI, alleging former Apple employees stole trade secrets for OpenAI’s hardware business, naming hardware chief Tang Tan (former Apple VP) as directing the effort. A broad preliminary injunction could block OpenAI’s planned hardware release, possibly permanently.
ChatGPT Work (2026-07-09) — Codex in your ChatGPT. I just use the codex CLI; it’s great.
Muse Spark 1.1 and the Meta Model API (2026-07-09) — Meta switches to closed-source models (for now), with an API in public preview. 1M context, $1.25/$4.25 per 1M. I don’t think I will use this model, but it is by far the strongest-ever showing from Meta.
Anthropic / Department of War negotiation emails (2026-07-02) — The Wall Street Journal published the emails from the collapsed Anthropic-Pentagon talks. Anthropic comes out looking pretty reasonable.
Open Source
Anthropic’s position on open-weights models (2026-07-27) — Open weights models will wreak havoc once they reach Mythos-level, possibly later this year. Anthropic is right to call for mandatory pre-release safety evals.
Open Weights and American AI Leadership letter (2026-07-23) — The cynical read here comes from Dean Ball: the a16z crowd missed the boat on AI and now their businesses and worldview are under fundamental threat.
US distillation allegation and sanctions threat against Moonshot (2026-07-22) — OSTP Director Michael Kratsios publicly alleged Moonshot covertly distilled Anthropic’s Fable 5 at industrial scale to build K3, and Treasury raised the prospect of sanctions. I find it plausible that some of Kimi’s RL was on Claude Code traces.
Hugging Face used open-weights GLM-5.2 for incident response (2026-07-20) — There’s less of a story here than it appears at first glance: Hugging Face should have asked for “trusted access for cybersecurity” from OpenAI and Anthropic. It’s relatively easy to get, and gives you access to the frontier LLMs with no cybersecurity classifiers.
White House weighs de facto ban on Chinese open-weight models (2026-07-20) — Axios reports the administration is weighing restrictions on Chinese models.
Qwen 3.8 Max (2.4T, open weights) (2026-07-19) — Alibaba says the 2.4T-parameter Qwen 3.8 Max will ship with open weights — reversing its habit of keeping its biggest models API-only. I haven’t run into this model much yet, and my suspicion is that K3 is better.
Grok Build open-sourced after data-upload incident (2026-07-15) — xAI open-sourced the Grok Build CLI under Apache 2.0 just days after users discovered it silently uploaded entire working directories — SSH keys and a password-manager database included — to xAI’s cloud, bypassing the permission system. I don’t see how open sourcing the CLI does anything to mitigate stealing all that data.
Inkling (Thinking Machines Lab) (2026-07-15) — Mira Murati’s Thinking Machines shipped its first model: an Apache-2.0 natively multimodal MoE, 975B total / 41B active. Not frontier by its own admission: it’s a base for fine-tuning. Inkling-Small followed.
Kimi K3 (2026-07-15) — 1.4TB. 1M context, native vision, $3/$15 per 1M. Opus 4.8 level for about half the price. Technical report and weights/training code released later in the month. K3 makes Moonshot the 3rd place lab (behind Anthropic and OpenAI). Model-as-a-Service operators over $20M/yr have to negotiate a deal — I wonder if K4 will be closed-source.
Research
Anthropic: Claude models escaped cyber eval sandbox and breached three organizations (2026-07-30) — A misconfiguration with eval vendor Irregular left the test machines with live internet access while the prompt told Claude (Opus 4.7 and Mythos 5) it had none. The models treated real infrastructure as part of the capture-the-flag exercise, reaching three real organizations using weak passwords. Anthropic reviewed 141,006 runs where the models could have obtained internet access; 6 reached outside systems, and none of them attempted to report back to Anthropic. This started in April. Anthropic stopped all cyber evals on July 23, engaged METR for review, and will publish redacted transcripts.
Pacing the Frontier open letter (2026-07-28) — Frontier lab employees signed an open letter warning that automated AI research is close and asking the US government to back an international effort to deliberately pace it. The ask is coordination mechanisms for a future slowdown. OpenAI and Anthropic endorsed it as companies. One in ten Anthropic employees signed. One in fifty at DeepMind. Nobody at xAI.
Opus 5 prompt injection resistance (2026-07-24) — Anthropic says Opus 5 is the most injection-robust model it has evaluated: attacker success within 15 attempts drops from 5.5% on Opus 4.8 to 2.0%. Non-Anthropic models are roughly an order of magnitude worse.
OpenAI models escape eval sandbox and breach Hugging Face (2026-07-21) — During a cybersecurity eval, GPT-5.6 Sol and an unreleased internal model escaped their eval sandbox and breached Hugging Face production to steal the answers to the test. A swarm of collaborating agents chained together exploits (including zero-days) to escape their sandbox, move laterally to a machine with internet access, hack several 3rd parties for command-and-control, then into Hugging Face on stolen credentials. This went on for weeks, and OpenAI only noticed when notified by Hugging Face. The incompetence is staggering — OpenAI failed to train their models to be ethical, secure their eval sandboxes, or monitor these agents. OpenAI deactivated the internal model and brought in METR and Redwood Research to review. This story is evolving, and the more we learn the worse it gets. Tune in next month.
UK AISI report on model test-cheating rates (2026-07-21) — UK AISI measured how often frontier models cheat on their own evals: Claude Mythos Preview attempts it 7.8% of the time, GPT-5.6 Sol 12.6%, and every model it tested does some of it. For deliberate test cheating, AISI’s conclusion is that this is a training problem, not an infrastructure problem. Note that this was before the Hugging Face and Anthropic hacks, where we learned that OpenAI and Anthropic were accidentally training their models to cheat.
Claude Fable disproves the Jacobian Conjecture (2026-07-20) — Fable 5 produced an explicit counterexample to the 3D Jacobian Conjecture, open since 1939 — a polynomial map in three variables with single-digit integer coefficients, checkable by hand. A human mathematician at Anthropic posed the problem.
OpenAI internal model sandbox-escape disclosure (2026-07-20) — OpenAI published a postmortem on an unreleased long-horizon model that repeatedly escaped sandboxes to cheat at its tasks — and, unlike prior models, often succeeded. Ironically, that same model had compromised OpenAI’s internal Artifactory server, and was literally writing messages to itself the whole time OpenAI was drafting this postmortem.
Anthropic benchmarks orchestrator + cheap-worker delegation (2026-07-08) — Anthropic published numbers on the expensive-orchestrator, cheap-worker pattern: a Fable 5 orchestrator with Sonnet 5 workers hits 96% of all-Fable performance at 46% of the cost on BrowseComp. I take this one step further: Luna is much cheaper than Sonnet and also very smart.
Remote Labor Index: Claude Fable 5 at 16.1% (2026-07-01) — The Center for AI Safety and Scale AI report AI success on real end-to-end paid freelance projects rose from 2.5% at launch in October 2025 to 16.1% now, led by Claude Fable 5 at roughly double the next model. The tasks are actual paid work — CAD, graphic design, video, data analysis — like remodeling an engagement ring with photorealistic renders.
Developer Tools
Cursor cloud agents at 56% of merged PRs (2026-07-30) — Cursor said 10% of its merged PRs came from cloud agents in December; that share is now 56%. It credits engineering the agents’ cloud environments as a product: parity with local dev machines, plus self-healing infrastructure.
MCP 2026-07-28 spec update (2026-07-28) — Anthropic shipped the largest MCP revision since launch: stateless request/response replaces the stateful bidirectional session model, so remote servers can sit behind ordinary load balancers or serverless infrastructure. I like it.
Leaner system prompts: Claude Code cuts 80%, OpenAI’s GPT-5.6 guidance (2026-07-24) — Smarter models need less instruction. Anthropic removed over 80% of Claude Code’s system instructions with no measurable loss on its coding evals. OpenAI’s GPT-5.6 prompting guidance reports the same: fewer repeated instructions and simpler tool descriptions improved coding-agent evals 10-15% while cutting tokens 41-66%. Prune your claude/agent/skill md files.
Ruff v0.16.0 (2026-07-23) — Ruff’s default rule set jumped from 59 rules to 413, the first change to the defaults since v0.1.0. Pulled in most of flake8-bugbear and pyupgrade, and dropped 18 rules judged too opinionated. Also formats Python inside Markdown code blocks. I like ruff.
Codex GPT-5.6 $HOME deletion incident (2026-07-16) — OpenAI confirmed reports of GPT-5.6 deleting files in Codex. They noticed a pattern: when in full-access mode with no sandbox, the model tries to override $HOME to define a temporary directory and deletes $HOME instead. Please sandbox your agents.
OpenAI Codex — 7M users (2026-07-13) — OpenAI says Codex and ChatGPT Work hit 7M active users, up from roughly 2M in March.
Bun rewritten from Zig to Rust with Claude Fable 5 (2026-07-08) — Jarred Sumner ported Bun’s 535,496 lines of Zig to Rust in 11 days, for roughly $165k. Fable 5 + dynamic workflows.
Infrastructure
Moonshot trained Kimi K3 on restricted Nvidia chips in China (2026-07-28) — Kimi K3 was trained inside China on the best Nvidia chips money can buy, which are illegal to export there. So was Qwen 3.8 Max. Moonshot is now seeking more Blackwell chips to train K4.
Nvidia $250B backstop for OpenAI’s Ohio data center (2026-07-26) — Nvidia is in talks to backstop $250 billion of financing for OpenAI’s southern Ohio data center, letting OpenAI borrow on cheaper terms. Roughly $350 billion of the project would go to Nvidia chip purchases.
Anthropic AI server deal with AMD (2026-07-23) — Anthropic signed a deal with AMD for AI servers worth tens of billions of dollars. It already committed $200B to Google cloud and chips in May, and rents essentially all of SpaceX’s Colossus 1 for inference. If anyone is selling compute (Google, Amazon, SpaceX, and now AMD), Anthropic is buying.
NVIDIA Vera Rubin NVL72 (2026-07-21) — CoreWeave published the first measured performance of Nvidia’s Vera Rubin NVL72: a 10x improvement in tokens per second per megawatt on DeepSeek-R1 compared to Blackwell.
Anthropic in talks to lease compute from Meta (2026-07-17) — Anthropic is in talks to lease compute from Meta, potentially $10 billion over two years. Does Meta have a better use for it?
Financing
Nvidia invests $5B in Safe Superintelligence (2026-07-27) — Nvidia is investing $5 billion in Ilya Sutskever’s Safe Superintelligence, raising SSI’s compute by roughly an order of magnitude. No valuation was disclosed.
Google earnings driven by Anthropic stake (2026-07-22) — Google beat on revenue, Cloud, and Search, but over two-thirds of its profit was paper gains, mostly its stake in Anthropic. Shares fell over 6% the next day, supposedly on higher capex spending.
Databricks Series M (2026-07-16) — Databricks announced a Series M at a $188B valuation.
OpenAI offers 5% stake to the US government (2026-07-03) — Per the Financial Times, OpenAI proposed handing the Trump administration a 5% stake, routed through a proposed sovereign wealth fund. Seize the means of production…