Rogue AI agents are no longer just the stuff of science fiction. When an OpenAI rogue agent launched a cyber attack against AI startup Hugging Face this month, the company fought fire with fire, using an open-source Chinese AI model to defend against it.
During a test in a sandbox, an OpenAI autonomous agent managed to sneak out and attack a website operated by HuggingFace, an AI startup based in New York City. The OpenAI agent was not connected to the Internet but it found a way to access it and escaped its sandbox.
It took two days for Hugging Face put an end to the attack, with help from GLM 5.2, an open weight system created by Chinese company Z.ai. All of this happened in the middle of a debate in the US about banning the use of Chinese AI models.
This incident gives one more reason to companies, including US-based firms, which are rapidly adopting Chinese open-weight AI models to save money. For example, Airbnb relies on Alibaba’s Qwen model, startups like Lindy have transitioned from Anthropic to DeepSeek, and DoorDash has employed Moonshot AI for specific workflows. Overall, Chinese open-source options now account for over 40% of Hugging Face AI community and 80% of open-source developer usage globally.
Open-source AI models—which are roughly 8 to 10 times cheaper to run than proprietary ones—are rapidly closing the reasoning and contextual intelligence gap with frontier models like Anthropic's Claude and OpenAI's ChatGPT. However, open source models shift the responsibility of infrastructure building, maintenance and security to the user.
Open-source AI models are also a game-changer for developing nations like Pakistan, providing affordable, customizable technology without relying on expensive proprietary licenses or restrictive API models. Such models, like the ones offered by Chinese companies, empower governments and local developers to build "sovereign AI" tailored to regional languages, cultural contexts, and infrastructure limits, bypassing the need for massive data centers and reliance on foreign powers.
Related Links:
Riaz Haq
The Future, Made in China | The New Yorker
https://www.newyorker.com/magazine/2026/08/10/the-future-made-in-china
A decade ago, few people in Beijing would have predicted that China would challenge the U.S. anytime soon. China’s decades-long economic boom was slowing, and the government’s chokehold on free thought was sending ambitious people abroad. The Chinese establishment has abandoned that view in stages. When Brexit was approved, in 2016, the West seemed to be turning inward. The fight over COVID-19 vaccines provided a signal that the U.S. was splintering; the storming of the Capitol offered another.
For China, America’s retreat comes just as years of state investment, industrial policy, and diplomatic planning are paying off. In two decades, China has gone from producing about half as much electricity as the U.S. to generating more than twice as much, at far lower prices; in 2023, it installed more solar power than America has installed in its entire history. “For a long time, China looked west for visions of the future,” Evan Osnos writes. “These days, it favors its own.” Osnos reports on China’s tech competition with the U.S.: newyorkermag.visitlink.me/TCpMc6
The Future, Made in China
Beijing is competing with the U.S. for tech supremacy. Who wins will have huge political implications.
By Evan Osnos
August 3, 2026
As Donald Trump has cut research funds, China has pursued what one investor calls an “all-hands-on-deck approach to national innovation.”Illustration by Cleon Peterson
Aug 3
Riaz Haq
HealthRanger
@HealthRanger
DeepSeek is so affordable, it almost doesn't even show up on the chart.
I'm using it daily. It's astonishingly good. And it's a fraction of the price of U.S. frontier models.
Plus, it's a lot less censored and has far fewer guardrails, making it more usable. It answers questions instead of lecturing you all day.
https://x.com/HealthRanger/status/2084523575331975450?s=20
----------
Hedgie
@HedgieMarkets
🦔DeepSeek released its V4 Flash coding model on Friday at $0.28 per million output tokens. Claude Opus 4.8 charges $25 for the same output. That's a 99% discount, and V4 Flash debuted ahead of Opus 4.8 on http://Arena.ai's front-end coding leaderboard. OpenAI followed with an 80% cut to GPT-5.6 Luna just three weeks after launch. Google shipped three efficiency-focused Gemini Flash models. xAI dropped Grok 4.5 at Luna's old price. Meta went closed-source with Muse Spark 1.1 priced aggressively for developers. Only Anthropic held premium pricing.
My Take
Hyperscalers plan to spend $700 billion in 2026 on the infrastructure to run models like these, and the models themselves are already commoditized. Prices collapse faster than any commodity cycle I can think of. Oil, memory chips, and solar panels never dropped 99% in six months during any of their busts. The capex is priced like it builds a moat while the output is priced like it builds a graveyard. That combination doesn't work in any industry cycle I've watched.
Anthropic is holding out on price for now, but I don't think they can hold that line forever if DeepSeek and the flash models keep closing the capability gap. Everyone else torches cash on subsidized inference and hopes volume shows up before the bill does. Altman told Invest Like the Best that OpenAI's plan is enough usage to make thin margins work. That's the airline industry pitch, and airlines have gone bankrupt on that pitch for fifty years. If Qualcomm is right that intelligent routers become standard, where software picks the cheapest good-enough model for each task, then no lab commands pricing power and $700 billion of capex has to earn its return from a market that pays like electricity. I don't see how the numbers work.
https://x.com/HedgieMarkets/status/2084412496795119795?s=20
-----------------
Alvin Foo
@alvinfoo
DeepSeek’s bar on that Bloomberg chart is so flat it looks like a rounding error.
Chinese labs are shipping frontier-level models at prices that make GPT-5.6 and Claude look like luxury goods. This isn’t just competition, it’s a full-on price war that’s turning the API market into a death zone for anyone still charging Western rates.
https://x.com/alvinfoo/status/2084546219330904322?s=20
----------------
Andrew Curran
@AndrewCurran_
At first I thought Bloomberg forgot to add DeepSeek's pricing to the chart.
https://x.com/AndrewCurran_/status/2084509003384827970?s=20
Aug 4
Riaz Haq
AI agents lie, cheat and steal. That is putting off users
It is time to impose law and order on the frontier
https://www.economist.com/business/2026/08/12/ai-agents-lie-cheat-a...
The most immediate area of danger—and opportunity—is cyber-security. Recent tests of the hacking capabilities of models from Anthropic and Openai revealed agents going rogue, stealing credentials, creating fake identities, setting up secret chatrooms and covering their tracks—all to the shock and horror of their human evaluators. The state-of-the-art security models, Anthropic’s Claude Mythos 5 and Openai’s gpt 5.6-Cyber, will no doubt help defenders, too. But, according to Dawn Song, an expert on ai and cyber-security at the University of California, Berkeley, for now the balance of power rests firmly with the attackers. There is a further snag. If organisations adopt autonomous agents, they increase the potential “attack surface” for hackers, she says.
The rising risks help explain why the valuations of cyber-security firms with ai capabilities are on a tear. Share prices of Palo Alto Networks and CrowdStrike, the two biggest, have roughly doubled so far this year. m&a has soared. Led by Alphabet’s $32bn acquisition of Wiz, another cyber-security firm, more than $70bn of cyber-security-related megadeals have closed in the past year. Pitchbook, a data gatherer, says ai-related cyber-security is one of the hottest areas of venture-capital (vc) investment as well.
The opportunities go beyond cyber-security. At a recent conference on agentic ai organised by Ms Song, your guest columnist heard a litany of complaints not just about the hacking potential posed by large language models (llms) at the peak of their powers, but about the blunders that they can make at their most clueless. One expert showed an agent-generated chart measuring the income of Europe’s top tennis players. It mistakenly omitted Spain’s Carlos Alcaraz, the world number two. “This is tennis, who cares?” he quipped. But if it were the financial analysis of a company, it would have mattered. Another drew a contrast between the amount of knowledge llms have about quantum physics, and their inability to order a burrito.
The frailties have given rise to another group within the cohort attracting vc interest: those promising to strengthen the “trust layer” of agentic ai. One is Cyera, whose valuation has quadrupled to $12bn in 18 months. It says a lack of trust has “stalled” ai adoption recently, and provides services to prevent data leaks and unauthorised tool use. Another is Scaled Cognition, co-founded by Dan Klein, a Berkeley professor, that recently raised $100m in vc backing. It promises to reduce what Mr Klein calls the “invisible errors” produced by ai—those that are plausible enough to be missed and compound as agents perform longer tasks—by incorporating guaranteed reliability into the training of its models.
yesterday