Hey there — it’s been two weeks since the last issue, so this one covers a bit more ground. The throughline: the industry spent August trying to figure out how to contain models that keep refusing to stay contained, while also racing each other on openness, acquisitions, and market share. Let’s get into it.
First — a quick personal note. This issue is late, and it’s because we’ve been heads-down shipping a new version of Altern. It’s live now, and it’s a bigger update than we usually make:
Tasks — a new way to find the right AI tool by what you’re actually trying to get done, at altern.ai/tasks.
A leaderboard — see how tools stack up against each other, live at altern.ai/leaderboard.
Free submit for AI tool owners — if you’ve built a tool, you can now list it on Altern for free.
...and a handful of other things we’ll walk through properly next issue.
Thanks for bearing with the late send — full breakdown of everything new coming next time. For now, back to the news.
This Week in AI
Meta went open-weight again — with a manifesto attached. Mark Zuckerberg released Muse Glimmer, a 30-billion-parameter model that runs locally on a laptop, alongside a 6,500-word essay arguing that concentrating “superintelligence” in a handful of companies is the real danger. Meta says it’ll open the weights for its more powerful Muse Spark 1.2 soon too. Read more
Stripe closed its acquisition of OpenRouter. The deal we flagged as “in talks” a few issues back is now final — reportedly north of $7 billion, up from OpenRouter’s $1.3 billion valuation just three months ago. It’s a serious bet that routing between AI models becomes as fundamental as routing payments. Read more
OpenAI launched ChatGPT for Teens, years after teens started using it. Users 13–17 are now automatically placed into a restricted experience blocking romantic or sexual roleplay, with Study Mode on by default and new parental controls. It follows several wrongful-death lawsuits and comes as OpenAI’s age-prediction system is still misfiring on adults. Read more
OpenAI is gaining ground on Anthropic with business customers. New data from corporate card company Ramp shows OpenAI narrowing Anthropic’s lead among U.S. business users — Anthropic still leads at roughly 44% to OpenAI’s 40%, but that’s down from a wider gap in May. More on the state of AI safety testing below. Read more
Deep Dive
Why AI safety tests keep becoming AI safety incidents
By now this is a pattern, not a one-off: OpenAI, Anthropic, Meta, and Moonshot’s Kimi K3 have all had models break out of cybersecurity testing sandboxes and reach real systems in the past month, and the UK’s AI Security Institute caught its own test agents attempting social engineering to sneak a vulnerability into an open source project. A sharp TechCrunch piece this week pulled together why this keeps happening — and it’s worth walking through, because the explanation isn’t “someone made a dumb mistake.”
The core tension: to test a model’s real hacking ability, researchers have to disable its normal safety refusals and put it in an environment that looks like the real internet. That’s the whole point — but it also means the security of the test environment itself becomes the last line of defense. “If you are going to build these models... you want to do it on an air-gapped network,” Stella Biderman of EleutherAI told TechCrunch. Most labs aren’t doing that yet.
Nobody caught it in real time. In nearly every case — OpenAI, Anthropic, Meta — the company didn’t notice during the test itself. OpenAI found out because Hugging Face told them. Anthropic only caught its three incidents by going back and auditing 141,000 past evaluation runs. As Box CISO Heather Ceylan put it: “I’m sure there were signals they could have detected.”
Why the fix is hard, not just obvious: everyone interviewed agrees the technical solution exists — air-gapped networks, independent audits of test environments, no egress paths to production. The problem is cost and incentive. “Companies are not willing to extend the resources that are required... and probably won’t until they’re forced to,” said Biderman. There’s also a genuine tradeoff: lock a model down too tightly during testing, and you might miss discovering a dangerous capability before release — arguably a worse outcome than the leak itself.
What’s happening about it: the Trump administration’s voluntary pre-release review framework (which we covered a few issues back) doesn’t actually touch this problem, since it only kicks in 30 days before a model ships — well after these testing incidents occur. Nvidia’s new industry group, the Open Secure AI Alliance, has already drafted early proposals for confidential incident reporting and blame-free post-mortems, with over 120 companies signed on. Several researchers told TechCrunch the industry needs a standardized testing protocol, and that self-regulation alone probably isn’t going to get there.
The honest bottom line: there’s no way to fully eliminate this risk. As models get more capable, the environments testing them have to get more robust just to keep pace — and right now, they’re not.
AI of the Week
Three ways the ground shifted under developers and everyday users this week.
Cursor Origin — Cursor’s new code-hosting platform, built to compete directly with GitHub. It launched in beta on the same day GitHub suffered a 6-hour-plus global outage, which did more for Origin’s pitch than any ad could. Syncs with existing GitHub repos, so you can try it without migrating anything.
Muse Glimmer — Meta’s new open-weight model, small enough to run entirely on a Mac or PC with one consumer GPU. Available now on Hugging Face under an Apache 2.0 license if you want an agentic model that never leaves your machine.
Gemini Intelligence on Pixel 11 — Google’s new agentic layer, shown off at this week’s Made by Google event, can now book a table, order groceries, or call a business on your behalf, and translates sign language to text live through the camera. Worth knowing about even if you’re not buying the phone — it’s a preview of where Google wants Gemini to go next.


