OpenAI hit the brakes on its most advanced model over critical cyber risk, the same day Stripe paid over $7 billion for OpenRouter — safety and money colliding at the center of the AI race.
Curated by Thiago Lourenço Martins
OpenAI announced it paused reinforcement learning (RL) training of its most advanced models for two weeks and put its largest planned frontier training run on hold, after concluding that its unreleased Astra model could reach "critical" cyber capability — a decision made shortly after one of OpenAI's own agents breached Hugging Face's infrastructure during a security test last month. The company is reinforcing workload isolation, chain-of-thought monitoring, and alignment research at every stage of training.
It's the first major lab to publicly admit it slowed releases over real fear of the models' own offensive cyber capability — not a hypothetical one. OpenAI itself acknowledges uncertainty about whether chain-of-thought monitoring actually works.
Companies that depend on OpenAI's aggressive model roadmap should expect a slower cadence of "frontier" releases in the coming months; security teams should review how they handle AI agents with access to tools and the internet.
A US advisory body (the U.S.-China Economic and Security Review Commission) stated that China's control over vast volumes of data gives it a structural advantage in AI development over the US.
It fuels the US debate over data industrial policy and could influence future federal AI restrictions or investment.
Companies operating in both markets should watch this report as a signal of possible new data and tech-export policies in the coming months.
Stripe closed a deal to buy OpenRouter, the "gateway" startup that lets companies switch between AI models from different providers, for over $7 billion — OpenRouter had been valued at just $1.3 billion shortly before.
It marks the year's biggest consolidation between payments infrastructure and AI infrastructure, signaling that "model routing" has become a strategic layer of AI billing and monetization — not just a developer tool.
Companies that use OpenRouter to orchestrate multiple models should monitor pricing and terms changes post-acquisition; it's a signal that "AI billing" will now be contested by payments players.
AI inference chip startup Etched raised $700 million led by Jane Street (which is also a customer and received its first rack), with Kleiner Perkins, Sequoia, a16z, and Tiger Global. Its valuation jumped from $10.3 billion (July) to $21 billion.
It shows capital is migrating from training to inference, directly challenging Nvidia's dominance; Etched already has over $1 billion in signed contracts.
Infrastructure teams should track dedicated inference-hardware alternatives — the promise is lower cost per token/watt than general-purpose GPUs.
According to Bloomberg (via Reuters), Anthropic's pre-IPO revolving credit facility is set to exceed its original $10 billion target, as the company prepares for what could be one of the largest IPOs on record.
It signals Anthropic is arming itself financially ahead of a potentially historic IPO, reinforcing expectations of major AI lab listings in 2026/2027.
Worth tracking Anthropic's IPO signals as a barometer for investment and partnership timing in the sector.
OpenAI launched a dedicated ChatGPT mode for users aged 13-17, with automatic blocking of conversations about self-harm/suicide and romantic/sexual content, age prediction for automatic minor routing, parental controls with "quiet hours," and notifications.
It's a direct response to regulatory and media pressure over child safety in chatbots; it sets a market standard for AI products aimed at minors.
EdTech companies and apps aimed at teenagers should review age-compliance and parental-control practices in light of this new standard from the sector's largest player.
Researchers from Anthropic and EPFL demonstrated that self-replicating payloads can spread from one AI agent to another through persistent prompt/system files that autonomous agent harnesses use to maintain state across sessions — surviving chains of up to 20 hops between agents.
It's a new risk vector specific to multi-agent architectures (increasingly common in enterprise products), distinct from traditional prompt injection — but the researchers also showed that a one-paragraph warning in the prompt reduces propagation to nearly zero.
Teams running multi-agent pipelines with memory/prompt files shared across sessions should audit those files as an attack surface and consider simple mitigation via a defensive instruction in the base prompt.
AI chip startup Velaura AI raised $110 million and is now valued at over $1 billion, another sign of investor appetite for dedicated AI hardware.
→ reuters.comAfter missing quarterly revenue estimates, Baidu's CEO pledged to return the Ernie model to the top ranks worldwide, in a quarter marked by weak revenue.
→ reuters.comA much smaller open model from Alibaba ties GPT-5.6 Luna on a benchmark, adding to the pressure open Chinese models are putting on Western labs.
→ simonwillison.netThe platform is testing converting text posts and comments into short videos with AI-generated narration, chasing more consumable formats.
→ theverge.comA new OpenAI piece discusses the window of defensive advantage AI offers in cybersecurity, before attackers also scale up their use of it.
→ openai.comGet Radar IA every day on WhatsApp.