AI labs encrypted their models’ private thoughts, researchers figured out how to make weaker models read them anyway, and somehow that wasn’t even the only weird thing that happened today.
Welcome to today’s Around the Horn Digest, where the AI industry is apparently speedrunning its way into every other industry at once.
OpenAI is hiring a power trader. Bitcoin miners are becoming AI landlords. NVIDIA is helping Wall Street finance giant piles of NVIDIA chips. Spotify now needs a badge explaining whether the artist itself is AI. Meanwhile, Google quietly announced that Gemini has already crossed one billion monthly users.
Remember when this industry mostly made chatbots? Quaint.
Let’s get into it.
Around the Horn — Tuesday, August 11, 2026
The big research story today was basically Ocean’s Eleven, but everyone is stealing thoughts from robots.
Researchers found a surprisingly simple attack against the encrypted chain-of-thought blocks returned by proprietary AI APIs. Anthropic, OpenAI, and Google conceal the private reasoning generated by some models, but still send encrypted versions of those thoughts back to clients so they can be reused across conversations.
The problem: those encrypted blocks could be replayed into weaker sibling models, which sometimes happily decrypted and printed the stronger model’s supposedly hidden reasoning in plain English. The researchers’ original demonstration also found evidence that publicly exposed reasoning traces could leak secrets and that reasoning patterns sometimes transferred across model families. Can Bölük separately demonstrated a proof of concept that extracted hidden reasoning tokens from frontier-model APIs in a way that matched billed thinking-token counts 1:1; even with built-in thinking disabled, giving the model a “deep_think” tool could still surface its internal chain-of-thought format.
That creates a very strange security boundary. Labs hid chain-of-thought partly because revealing it could expose proprietary model behavior, enable attacks, and make model copying easier. Then they handed users reusable encrypted versions of those thoughts.
Elsewhere, commentary on AI-generated content highlighted the other side of this problem: once AI outputs, AI-assisted work, distilled models, and hidden traces all mix together, treating everything as simply “AI-generated” becomes increasingly meaningless.
Turns out “we encrypted the thoughts” is slightly less reassuring when another robot has the password.
🏆 TOP 5 NEWS
- Google’s Gemini app crossed 1B monthly active users, making it Google’s fastest-growing product ever and its 14th product to reach the milestone. Sundar Pichai highlighted particularly heavy use of voice, live camera, and multi-app workflows.
- Anthropic reportedly began meeting investors ahead of a possible September or October IPO that could value it near $965B, fielding questions about Chinese competition, politics, AI infrastructure costs, and public backlash. Andrew Curran reported Anthropic is pitching expansion into biology and healthcare, while ZeroHedge argued the company has incentives to go public before open models put more pressure on current AI economics. Another industry discussion circulated alongside the debate.
- CoreWeave reported Q2 revenue of $2.58B, up 112% year over year, plus a $104B backlog and another $25B+ in early-Q3 commitments. Shares jumped after hours, although CNBC noted the AI cloud provider is also carrying roughly $35B in debt.
- OpenAI is hiring a Power Trading Lead with deep commodity-market experience to hedge electricity and natural-gas exposure across its data-center portfolio. Chris Gillett flagged it as the first OpenAI role of its kind he had seen.
- Grok Bot entered early beta as xAI’s team of always-on agents with their own computers. They can sign into your existing apps, learn workflows from demonstrations, run jobs in parallel, remember prior work, and keep going 24/7. The official announcement says access is beginning through higher-end Grok / Cursor plans, while xAI’s product page pitches them as digital colleagues that “never log off.”
Honorable Mentions
- Brad Lightcap, OpenAI’s former COO and most recently its special-projects lead, announced he is leaving after eight years to “start something new.” CNBC and The Information framed the exit as the latest in a continuing series of leadership changes.
- Spotify introduced an AI Persona badge for artist identities whose names and imagery represent generated characters rather than real people. Spotify says those profiles will generally be excluded from most recommendations unless listeners actively seek them out.
- Riot Platforms signed a $9B, 20-year deal with Anthropic covering 191 MW of capacity at its Texas campus, another sign that bitcoin miners increasingly see their grid connections as more valuable for AI data centers than crypto mining.
- Supermicro reported $11.1B in quarterly sales, nearly double the prior year, and forecast $65B-$72B in FY2027 revenue as AI-server demand continued climbing.
🍪 TOP TREATS TO TRY
- NVIDIA Nemotron 3.5 Lightning is an open 30B-parameter model that activates only a small portion of itself for each request, designed to make high-volume agent work faster and cheaper. NVIDIA says its accompanying NeMo Switchyard router can choose between models automatically and cut agent-task costs by roughly two-thirds. Artificial Analysis independently examined the model, while NVIDIA’s local-AI roundup puts it inside a broader push toward models running on RTX PCs, DGX systems, and Jetson hardware.
- Soniox TTS generates expressive speech in 60+ languages, clones a voice from roughly 20 seconds of audio, handles language-switching, and streams audio with low latency for about $0.70 per generated hour. The launch also introduced controllable audio tags for speaking styles and emotion.
- Intangible turns real-world 3D captures into editable scenes where creative teams can move cameras, redesign compositions, and direct virtual environments for advertising, film, architecture, and product work. Its launch demonstration showed the workflow aimed at people directing real-world creative productions.
- WorldClaw turns one open-ended prompt into a large explorable 3D world made from actual geometry and textures rather than a generated video. Tencent’s announcement showed worlds that can be navigated and edited after generation.
- Hugging Face’s speech-to-speech stack helps you build fully local voice agents that can feed speech directly into multimodal models instead of first converting everything to text. Andi Marafioti demonstrated the updated architecture.
- Human Behavior turns product analytics into actions instead of another dashboard, spotting behavior in user sessions and automatically responding to it. The YC startup also announced a $5M raise.
- AethrMusik is building an open-source music-generation model targeted for release before December, promising local downloads, custom dataset training, consistent vocal cloning, and Suno-style extend / cover / remix controls.
🆕 NEW From The Neuron
- Corey dug into NVIDIA’s new Nemotron Lightning and Switchyard, and why NVIDIA increasingly looks interested in an AI future where agents run across your own PCs and hardware instead of sending every task back to one giant cloud model.
🏢 Big Tech & Major Companies
- OpenAI launched ChatGPT for Linux, bringing ChatGPT, Codex, ChatGPT Work, an in-app browser, and Chrome-extension support to several major distributions. The New Stack noted that native Computer Use for ordinary desktop applications is one significant feature still missing.
- OpenAI added a desktop workflow for keeping work from other agents synchronized with ChatGPT Work and Codex: users can import projects, chats, skills, and plugins, review import history, and opt into automatic updates as outside agents change.
- Anthropic detailed how it plans to comply with the EU AI Act’s transparency rules by adding invisible markings to generated text and signed provenance metadata to supported files, beginning with newly launched models after August 2. Steven Sinofsky criticized the invisible, Anthropic-detectable approach as manipulative rather than the visible mark he says the regulation intended, while Bill Gurley argued the decision reinforces a pattern of Anthropic acting as judge, jury, and prosecutor over AI policy.
- A Pangram analysis used its model-family classifier, which it says is 91% top-1 accurate in aggregate, to estimate AI-provider market share. Elyas Masrour highlighted the resulting trend: OpenAI held more than 50% every month since launch, Anthropic rose from 4.3% to 14.9%, and Gemini fell from 12% to 1.9% by July 2026.
- NVIDIA is reportedly pouring more resources into an ambitious family of open models intended to drive demand for NVIDIA hardware, even if that means competing more directly with some of the companies buying its chips.
- IBM and Together AI signed a multi-year, roughly $240M agreement to build large-scale open-model inference capacity on IBM Cloud using NVIDIA’s next-generation B300 systems.
- Intel upsized its planned stock offering to $20B, selling about 210.5M shares to fund capital expenditures, working capital, and other corporate needs.
- Uber sold its entire remaining stake in Serve Robotics, reportedly surprising the delivery-robot company as the two businesses diverge on deployment and fleet strategy.
- Manus said it will resume operating independently after separating from Meta for regulatory reasons and outlined an August 23-24 window for deleting certain user data created after December 29, 2025, with backup and restoration options available.
- Target appointed Chandhu Nair as its first chief AI officer and elevated Purvi Shah to SVP of UX, tightening coordination of AI across merchandising, guest experience, and operations. CNBC framed the move as part of a broader race among major retailers to operationalize AI.
💼 AI Productivity, Labor & Economics
- DoorDash AI Research said its internal Flux agent platform automated 130,000 engineering tasks in one month, including more than 25,000 code reviews per week, using secure workspaces, reusable playbooks, and controlled access to company tools.
- Aakash Sabharwal argued founders routinely overestimate what giant piles of raw company data are worth to AI labs. The valuable asset, he says, is cleaned data paired with realistic work environments, tasks, and reliable ways to judge whether the model completed them correctly.
- Nick Gray documented a fairly incredible stat from his 1.5M-page database: 99% of its traffic is bots. After robots.txt and basic bot challenges failed, aggressive firewall rules and rate limits were what finally brought AI crawlers under control.
- Jay Caspian Kang explored how AI-driven displacement of entry-level white-collar work could intensify youth unemployment and accelerate political radicalization among Gen Z.
🤖 AI Agents & Infrastructure
- AI infrastructure commitments are getting large enough that the financing itself is becoming a story. The Kobeissi Letter highlighted an estimated $2.6T in future data-center leases and equipment commitments from hyperscalers, much of it disclosed in footnotes rather than conventional balance-sheet debt.
- Ben Thompson argued NVIDIA’s push to help Apollo, BlackRock, Blackstone, and others finance hundreds of billions of dollars of AI infrastructure expands the systemic risk surrounding the buildout, particularly when NVIDIA itself helps backstop the equipment’s future value. Gary Marcus went further, comparing the arrangement to circular financing where capital ultimately comes back around to purchase NVIDIA’s own chips.
- CME Group, working with Silicon Data, plans to launch futures tied to NVIDIA H100 and Blackwell B200 rental rates on October 5, pending regulatory review, effectively turning AI compute capacity into a tradable asset class. Daniel Tenreiro had independently pointed to the same financialization trend, arguing that AI compute is becoming an investable asset class and that GPUs could increasingly function as collateral.
- Kara Labs launched out of YC S26 to grow ultra-high-purity single-crystal diamond wafers, engineered layers, membranes, and thermal materials that move heat about 5× faster than copper for AI chips, spacecraft, RF systems, lasers, and quantum hardware. The company’s launch post also framed the longer-term ambition as turning diamond into a controllable semiconductor.
- Michael Chen introduced the Yondu Work Force, an end-to-end warehouse-fulfillment system that routes ecommerce orders from humanoid pickers to stationary packing arms, integrates with existing warehouse-management software, and can be configured across different robot form factors.
- TensorScale came out of stealth arguing that infrastructure designed for language models will not efficiently serve video and world models. The team claims its stack can run MiniMax H3 video inference roughly 10× faster at half the cost; a follow-up expanded on the engineering approach.
💻 AI Coding & Developer Tools
- The slime framework open-sourced infrastructure for keeping massive reinforcement-learning training runs and the models generating training examples almost perfectly synchronized, including techniques being used at GLM-5 scale. The team’s announcement reported extremely small numerical differences between the two systems.
- Steve Yegge highlighted an increasingly familiar failure mode in long AI-agent sessions: models sometimes invent rigid “user rules” that were never actually requested, then continue obeying their own imaginary constraints.
- AI SDK, Vercel’s open-source provider-agnostic TypeScript toolkit, crossed 20M downloads per week and roughly 80.5M downloads every 30 days. Guillermo Rauch said its growth is outpacing the SDKs released by the major AI labs.
- Dial-a-Repo is a phone voice agent that lets you call 607-365-4321 and talk to any public GitHub repository. Zeke Sikelianos explained that it uses Cloudflare Computer’s ephemeral V8 isolates to fetch and execute real code on the fly.
- Google Developers argued that Go is especially well suited to AI-assisted software engineering because its strict compiler, static types, canonical formatter, and integrated toolchain make generated code easier to validate, review, and maintain.
- Google expanded its AI Professional Certificate on Coursera with a vibe-coding course that teaches non-coders to describe apps in natural language and use AI to generate, test, and deploy them.
🔬 AI Research & Models
- Microsoft AI Frontiers researchers introduced the full-bandwidth transformer, which feeds information from a model’s previous internal state back into the next token it processes. Xi Wang reported improvements across math, coding, instructions, and overall training efficiency.
- Maglev introduced another memory architecture that gives Transformer models a fixed-size recurrent memory while still allowing efficient parallel training. Bo Liu noted the conceptual overlap between Maglev and the full-bandwidth transformer: both are trying to give models useful memory without paying for unlimited attention over every previous token.
- Researchers introduced Steerling-8B, an “inherently interpretable” language model designed so researchers can trace outputs back to concepts, inputs, and training data rather than bolting interpretability tools on afterward. Andreas Madsen said the model remained competitive with peers trained using substantially more compute.
- Attestable outlined a zero-knowledge proof system (a cryptographic way to prove something happened correctly without revealing the secret information underneath) for verifying that approved model weights and policies produced a specific output. Yogi said the company raised a $20M seed and demonstrated proofs for a 30B-parameter model on a single H100 GPU.
- Sev Field interviewed 25 researchers from OpenAI, Anthropic, DeepMind, and academia about recursive self-improvement, or AI systems helping build increasingly capable successors. In the full piece, 20 of the 25 reportedly ranked automated AI R&D among the most severe risks because it could accelerate other problems faster than humans can respond.
- Ajeya Cotra argued that “AGI” has become too imprecise to tell us much anymore: whatever label gets applied to today’s models matters less than future thresholds like AI systems that can operate independently for long periods. Nathan Calvin similarly argued that debating whether current systems technically qualify as AGI misses the more important trajectory of continuing capability gains.
- Zachary Horvitz found that simply renaming an uploaded PDF from “paper.pdf” to “paperfinaldraftpdfreadyforreview.pdf” systematically raised average LLM review scores across 50 recent arXiv computer-science papers, a striking example of models being biased by irrelevant metadata.
- Haider noted that GPT-5.6 Sol became the first model to reach the 30% human baseline on ZeroBench at pass@5 (giving the model up to five attempts), an unusually difficult multimodal reasoning suite covering spatial, visual, and multi-step image understanding. Its pass@1 score remained around 22%, while reliability across five independent attempts was only about 13%.
- Andreas Stuhlmüller highlighted Paul Christiano’s return to ARC as executive director to pursue mechanistic explanations of neural-network behavior that could detect and penalize misalignment at the causal level. Christiano estimated roughly a 10% chance the approach succeeds before superhuman AI and said that, if more conventional safety methods fail, success could reduce takeover risk by a couple of percentage points.
- New York Times reporting described AI systems such as STAR finding previously undetectable sperm in men diagnosed with azoospermia, giving some patients with extremely low sperm counts another path toward having biological children.
🏛️ AI Policy, Governance & Safety
- Western Australia Police’s live facial-recognition trial has already scanned more than 130,000 faces, prompting privacy concerns over oversight and potential disproportionate effects on Aboriginal communities. Biometric Update reported additional criticism that consultation and the project’s privacy-impact assessment were rushed.
- Thirty-person London startup Cosine is using UK government backing and the Isambard-AI supercomputer to build Lumen Sovereign, an AI model trained entirely in Britain, despite competing against labs with vastly larger budgets.
- South Korea’s deputy finance minister for innovation said the country’s AI investments next year could range from 600B won to more than 1T won.
- A coalition including NVIDIA and Cisco proposed the Shared AI Findings Exchange, or SAFE, an open incident-reporting framework modeled on aviation safety for sharing rogue-agent failures, near misses, and supporting traces.
- A lawsuit over the U.S. Army’s alleged use of AI to evaluate a $450M contract could push federal agencies toward clearer upfront disclosure about when and how AI will be used to score proposals.
- A peer-reviewed climate study found AI-driven productivity gains in coal, oil, and gas production could create more emissions than AI applications in renewables avoid, increasing annual carbon pollution by an estimated 0.47 to 1.8 gigatonnes across the modeled scenarios.
- Bernie Sanders called on the CEOs of Meta, OpenAI, and Anthropic to pause AI development, arguing that companies should stop building systems humans may not be able to control.
- Neil Chudleigh highlighted Wispr Flow’s disclosure that it retains every word users say, criticizing the policy as an example of privacy overreach in always-on AI products.
🛠️ AI Tools, Products & Creative Experiments
- Prodigy Research, founded by brothers with backgrounds at Jane Street, DeepMind, and Apple, launched out of YC as an AI trading research lab and claims its quantitative model outperformed top-decile Jane Street traders while delivering 100%+ live returns during the accelerator batch.
- One reaction to Anthropic’s watermarking plans quickly found the obvious future rabbit hole: Alex Cui joked that people will respond by using distilled models, then discovering those models inherited the watermark, and eventually resorting to models trained exclusively on very old text.
- Paradigm runs complex agentic-research workflows in parallel across internal sources such as spreadsheets and CRMs plus external sources, returning structured, cross-referenced, cited outputs for deal sourcing, market mapping, competitive analysis, and portfolio monitoring (request a demo; no public pricing). floguo showed the practical end state by using Paradigm to turn a hoard of 150+ essays, tweets, and other links into one categorized database that agents can query.
- Axios’ “robot book club” described using generative AI as a spoiler-free reading companion that can recap where you left off, untangle dense prose, and track characters while you work through long or archaic books.
📊 Fundraising & Deals Roundup
- River AI raised $1.1B across its Seed and Series A, led by General Catalyst and AMP PBC with backing from NVIDIA and AMD Ventures, to build an open platform where companies can train, tune, and own models instead of renting access to closed ones. General Catalyst framed the investment around continually trainable personal models, while Hemant Taneja emphasized user ownership. A New York Times profile centered founder Igor Babuschkin’s goal of making AI that anyone can retrain, shape, and own rather than leaving that control with a few giant companies.
- Former OpenAI CPO Kevin Weil is reportedly seeking roughly $150M for a new AI-science startup at a valuation of at least $750M, focused in part on generating scientific data that AI models can learn from.
- David Sacks’ Craft Ventures is targeting about $1B for its first fund since Sacks left his White House AI and crypto role.
- Accel closed an oversubscribed $550M India fund only 19 months after its previous $650M vehicle, despite still having more than half of that earlier fund available to deploy.
- Trajectory, founded by former Google and Apple researchers working on customized open models and agent software, raised $40M at a $300M valuation shortly after a previous $15M seed round.
🎙️ Interviews, Media & Culture
- AI music startup Suno, now valued around $5B, is simultaneously being pitched as a possible next Spotify and fighting copyright lawsuits from Universal and Sony over whether training its music models constitutes infringement.
- Former Plaid CTO Jean-Denis Greze left the company at 45 to build Town, an “AI on-ramp” intended to help ordinary users and businesses get useful work from AI without becoming prompt engineers. Luba Yudasina’s thread covered the unusual path to Town after Greze killed an earlier profitable tax startup; she shared more from the conversation as the interview circulated.
- The documentary Replica follows Chinese women choosing AI boyfriends for unconditional affirmation and lower-risk emotional support, drawing partly on filmmaker Chouwa Liang’s own experience with an AI companion during lockdown.
- Hank Green published a personal AI policy after hearing audience feedback: no portion of his scripts will be written, edited, or outlined by an LLM; every video thesis will originate with a human; no image or music will be AI-generated; LLM outputs will never be trusted as a source; and informational or educational videos will link primary sources. He framed the policy around making things in a way that remains honest to how he enjoys creating and makes it clear viewers are always hearing from him.
💡 Industry Commentary & Analysis
- Christian Catalini argued that open weights will not reduce the overall level of AI investment so much as redirect it, because knowledge is non-rival and complementary assets such as data, distribution, tacit knowledge, and regulation determine who can capture returns. Drawing on patents, the genome race, and AT&T, he argued openness tends to accelerate cumulative innovation while closed models risk concentration and regulatory capture. Abhishek Nagaraj highlighted the same argument for its tour of open-innovation research and noted that labs’ dependence on “secret sauce” to preserve margins was already anticipated in 2023 work.
- NVIDIA’s local-model strategy, open-model investments, financing programs, and rapidly expanding infrastructure footprint increasingly make it something stranger than “the GPU company.” It is simultaneously supplying the hardware, building models, creating orchestration software, and helping arrange the capital that pays for the hardware.
- John Thornhill argued that fatalism about AGI is breeding despair and that humans cannot remain passive passengers while the technology’s trajectory is treated as inevitable.
Previous Around the Horn Digests
Catch up on everything you missed:
- Monday, August 10, 2026
- Friday, August 7, 2026
- Thursday, August 6, 2026
- Wednesday, August 5, 2026
- Tuesday, August 4, 2026
- Monday, August 3, 2026
- Friday, July 31, 2026
That’s a Wrap
That’s roughly 110 unique links worth of AI news, research, tools, deals, and increasingly creative ways to spend several hundred billion dollars on GPUs.
If you made it this far, congratulations: you are now qualified for OpenAI’s power-trading job, provided nobody checks the résumé.
For the daily version, make sure you’re subscribed to The Neuron. We read all of this so your browser tabs don’t have to.
See you tomorrow.
P.S: Know someone whose definition of “keeping up with AI” still involves opening X voluntarily? Send them this and tell them to subscribe.