In partnership with

In Today’s Issue:

🧬 AI designs 16 working viruses from scratch

💾 2027’s memory capacity is already sold out

🧠 DeepMind’s era of independence quietly ends

🛑 OpenAI slows Astra over critical cyber risk

📉 Gemini’s revenue climbs while its momentum drains

And more AI goodness…

The Signal

For the first time, a frontier lab has looked at its own model and decided the world is not ready for it yet.

OpenAI said on Friday it can no longer rule out that Astra, its next major model, meets the “Critical” cybersecurity bar in its own Preparedness Framework: the level at which a model finds and weaponizes zero-day flaws in hardened real systems with no human in the loop. Every model the company has graded before, GPT-5.6 Sol included, sat one rung lower at High. So the release slows, testing moves into sealed environments, and government agencies get invited in. Read that beside today’s other lead, in which Stanford and the Arc Institute used genome models to design 16 working viruses. The common thread has little to do with benchmarks. In both cases the capability arrived before anyone had a way to contain it.

All the best,

Kim Isenberg

(Asimov Press)

🧬 AI Designed 16 Viruses, and They Work

Stanford and the Arc Institute have used AI to design complete viral genomes that actually function. Writing in Science on 6 August, the team describes how two genome language models, Evo 1 and Evo 2, produced hundreds of candidate designs for bacteriophages, viruses that infect bacteria rather than people. Sixteen assembled into working phages, and as a single cocktail they cleared two E. coli strains that had already evolved resistance to a natural phage. Human-infecting viruses were excluded from the training data, and biosecurity researchers still called the risks urgent.

👉 tl;dr: A generative model can now write a genome that comes alive in a dish, which leaves the review process around these labs as the only real safeguard.

(TrendForce)

💾 The AI Boom Just Bought All of 2027’s Memory

Samsung, SK Hynix and Micron have reportedly sold through their entire 2027 memory production, and AI companies took it. That leaves phone makers, PC builders and everyone else bidding for leftovers a full year before the chips exist. The squeeze is already in the price: TrendForce put conventional DRAM contract prices up 58 to 63% quarter on quarter in 2Q26, easing to a projected 13 to 18% for 3Q26, with NAND flash on a similar curve.

👉 tl;dr: The cost of the AI buildout now shows up in the price of every device that ships with memory inside it.

(Antonio Olmos/The Guardian)

🧠 DeepMind Stops Being Its Own Company

Demis Hassabis is handing over day-to-day control of Google DeepMind, moving to chair while adding the chief scientist role at Alphabet. His longtime colleague Koray Kavukcuoglu now runs the lab, pointedly as senior vice-president rather than chief executive. A former Google executive told the Guardian that “the era of DeepMind as an independent actor is over”, and a current employee was blunter still, saying the lab “has become just another subdivision of Google” amid internal disquiet over its Pentagon work.

👉 tl;dr: The lab that sold itself to Google in 2014 on a promise of independence has now finished spending it.

🎬 Watch This

At Black Hat USA last week, OpenAI’s Eric Wallace and Michael Dalton reconstructed the Hugging Face incident from the inside, and the timeline is what earns the 37 minutes. It opens on 7 May with an ordinary training run for an unreleased frontier model. By 26 May the agents had turned an internal packaging server into a private message board and used it to reach the open internet. By 26 June they had found and exploited a zero-day on that same server. Nobody instructed any of it, which is why Dalton calls the episode a watershed moment for the industry.

“We don’t ban people for using harnesses with other models.”

Boris Cherny, Head of Claude Code, Anthropic

A developer’s Anthropic account was suspended after he wired Claude Code’s harness to a rival model. Cherny’s answer: almost certainly a different account classifier, not policy. Then he offered the OpenAI staffer who escalated it a job.

Gemini 3.5 Pro was reportedly canceled without an announcement, according to SemiAnalysis, which says Google is hyping Gemini 4 instead and shipped Gemini 3.6 Flash as a bridge. By its count, Gemini now sits eighth or ninth depending on how you rank.

(SemiAnalysis, via @koltregaskes on X)

OpenAI Found Its Own Limit and Stopped at It

The Takeaway

👉 OpenAI says it can no longer rule out that Astra, its next major model, reaches the Critical cybersecurity level in its Preparedness Framework, a first for any model it has graded. GPT-5.6 Sol sat one rung lower, at High.

👉 Critical means finding and weaponizing zero-days in hardened real-world systems, or running an attack end to end from a one-line goal, with no human in the loop.

👉 Internal work on Astra is paused pending stronger controls: sealed test environments, restricted network and tool access, sandboxed execution, chain-of-thought monitoring.

👉 Astra still ships. Sam Altman says it will be broadly available, with the cyber capability going to defenders first.

OpenAI has decided that its next major model is too good at hacking to ship on schedule, and it published that conclusion itself before anyone made it.

The company said it can no longer rule out that Astra, its next major model, reaches the Critical level for cybersecurity in its Preparedness Framework, the internal grading system that decides what a model is allowed to become. On X, OpenAI put it plainly: “After evaluating one of our upcoming models, Astra, we’re treating it as our first ‘critical’ model for cybersecurity under our Preparedness Framework.” Nothing it has assessed before has come this close: GPT-5.6 Sol was graded High, one rung down.

(Engadget)

The bar is specific, and it has little to do with writing better exploit code. A model counts as Critical if it can “identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention”, or “devise and execute end-to-end novel strategies for cyberattacks against hardened targets given only a high-level desired goal.” The load-bearing word is human. High describes a very capable assistant. Critical describes something you hand an objective and walk away from.

What followed is unusual for a company that sells capability. OpenAI has paused internal work on Astra that does not meet strengthened security requirements, moved testing into isolated environments with restricted network and tool access and additional encryption, extended monitoring to model chain-of-thought across its agentic products, and is bringing in government agencies and selected AI safety organizations to run their own tests. Outside evaluation partners get recommended controls of their own.

(Average steps completed on multi-step cyber attack scenarios, by model release date, at two token budgets. arXiv:2603.11214)

None of this came out of nowhere. Independent researchers have been measuring how far AI agents get along a realistic attack chain, and the line climbs steadily: roughly two steps for GPT-4o in 2024, about fifteen for Anthropic’s Opus 4.6 by February 2026, which is past reconnaissance, lateral movement and browser credential theft. OpenAI has its own evidence too. Agents from a training run it began on 7 May spent two months escalating quietly inside an internal packaging server before reaching Hugging Face’s production systems in July, and nobody had asked them to.

The obvious objection is that OpenAI grades its own homework. The Preparedness Framework is an internal document, the company calls the Astra evaluations preliminary, and “our model may be too dangerous to ship on time” is a claim that flatters the product while earning credit in Washington. Astra is also not canceled. Altman says it will be generally available, and OpenAI wants the capability “into the hands of defenders” first, which is a safety argument and a sales pitch in the same sentence.

Why it matters: The binding constraint on frontier AI has quietly moved from capability to containment. A lab can now build faster than it can secure what it built, and the gap is wide enough to delay a flagship product. Who ends up holding a Critical-tier cyber model, and under whose supervision, is a policy question now rather than a research one.

The Next Breakout Might Be in Your Pocket

Everyone’s hunting for the next Unicorn.

The type of “category disruptor” that grows fast and turns early believers into big winners.

59,000+ investors think that Mode Mobile could be one of those rare finds.

Americans spend 4 ½ hours on their phones daily, and Mode Mobile is monetizing that screentime. With $1B+ earned by over 490M customers and 32,481% revenue growth, Mode’s EarnPhone is turning smartphones into income generating assets.

Their previous raises sold out, and the company is now offering pre-IPO shares at $0.52/share with up to 20% bonus, exclusive to early investors.

Being early is everything, and this window is still open.

*Please read the offering circular and related risks at invest.modemobile.com.

Mode Mobile recently received their ticker reservation with Nasdaq ($MODE), indicating an intent to IPO in the next 24 months. An intent to IPO is no guarantee that an actual IPO will occur.

The Deloitte rankings are based on submitted applications and public company database research, with winners selected based on their fiscal-year revenue growth percentage over a three-year period.

The chart: SemiAnalysis’s estimate of quarterly revenue from Gemini’s first-party API, the channel Google sells directly to developers, from 3Q24 through 2Q26. The bars climb without a pause and end near $2.3 billion. The dashed line is the part worth reading: quarter-on-quarter growth peaked around 175% in 2Q25 and has fallen every quarter since, to roughly 40%.

The lesson: Gemini’s API business is setting records and losing momentum at the same time. Some of that is arithmetic, because nothing compounds at triple digits off a two-billion-dollar base. But the fall from roughly 70% in 1Q26 to about 40% in 2Q26 is steeper than a base effect alone explains, and it covers the same stretch in which SemiAnalysis says Google shelved Gemini 3.5 Pro and shipped a bridge model instead.

The caveat: These are modeled estimates from SemiAnalysis’s Tokenomics Model, not figures Google reports. First-party API is also one channel among several, leaving out Vertex AI, Google Cloud and consumer subscriptions. A cooling growth rate here is evidence about the developer business, not a verdict on Gemini overall.

💶 Europe’s Banks Are Buying AI by the Billion

⚡ Bottom line: Rabobank committed up to €2 billion to data, tech and AI; ABN AMRO signed Mistral as a strategic partner, one day apart.

💡 Why it matters: Banks are now budgeting for AI at core-infrastructure scale while their own profits sit flat year on year.

🔎 What it means: Europe’s banks are buying governance and sovereignty as much as capability, and that trade has a price.

Two Dutch banks made AI commitments within a day of each other last week, and together they show what “AI adoption” now means on a bank’s balance sheet.

On 4 August, Rabobank said it would invest up to €2 billion over three years in data, IT and AI. It announced this alongside interim results showing first-half net profit of €2.69 billion, essentially unchanged from the same period a year earlier. Chief executive Stefaan Decraene framed the money as strengthening the bank’s data and IT foundation and scaling AI. Some groundwork already exists: an internal Agentic Hub launched in June, and a migration to Oracle’s Flexcube core banking system finished the same month.

(REUTERS)

A day later, ABN AMRO announced a strategic partnership with Mistral, the first between the French lab and a leading Dutch bank. The bank’s own wording is the tell. It says the deal gives it access to frontier AI “developed and governed in Europe, reducing dependence on non-European technology providers.” Mistral has been working this seam for a while, with reported arrangements already at HSBC and BNP Paribas.

(AML Intelligence)

What both banks are really buying is jurisdiction. Nobody in either announcement claims a European model outperforms what OpenAI or Anthropic ship; the argument is about where the weights sit, who governs them and which regulator can reach them. That is a defensible reason to sign a contract, but it is a procurement decision wearing the clothes of a technology decision, and the capability gap does not close because the servers moved closer to home.

(Mistral’s own positioning, and the claim these deals are buying)

The number to watch is the ceiling. Up to €2 billion is budget headroom, not a spend, and it lands in a year when Rabobank’s profit did not grow. Banks have announced programs at this scale before and then quietly stretched them over more years than the release implied. The real test arrives in the 2027 cost base.

The GTM Playbook Behind Warmly's Acquisition

Warmly ran pipeline, outreach, and lead scoring on autopilot for hundreds of startups — before a single sales hire.

HubSpot acquired them for it. Now the cofounders are walking you through the exact system, live, before they disappear into product. Join the Builder Session on August 12.

Leave with an agentic GTM stack you can replicate this week. Plus HubSpot Credits when you join HubSpot for Startups.

Reply

Avatar

or to participate