The day's tech, sifted: Jul 24, 2026
What matters today: Meta, Nvidia, Microsoft, a16z, and more than twenty other companies signed a letter defending open-weight AI, with Nvidia's Jensen Huang posting on X for the first time ever to say open models strengthen cybersecurity, a rare industry-wide response as China's Kimi K3 scrambles Silicon Valley and Washington alliances and isolates OpenAI and Anthropic. The same day, Black Forest Labs launched FLUX 3, a single model spanning video, image, and audio that already drives real robots on Audi's factory floor, while Anthropic shipped tool-connected voice mode for Claude and OpenAI put voice control on the desktop. Google disclosed $811 billion in contracted AI infrastructure spending, and word spread that OpenAI disclosed its Hugging Face breach later than first understood.
AI / LLMs
- Meta, Nvidia, Microsoft, a16z, and more than twenty other companies signed a joint letter defending open-weight AI against "premature restrictions," with Nvidia's Jensen Huang using his first-ever X post to argue open models strengthen cybersecurity; Newcomer's analysis explains why, China's Kimi K3 has gotten strong enough to scramble Silicon Valley and Washington alliances and isolate OpenAI and Anthropic from customers who want open weights.
- Black Forest Labs launched FLUX 3, a single flow model spanning video, image, and audio generation that the company says beats Runway Gen-4.5, Seedance 2.0, Gemini Omni, and Grok Imagine, and a mimic variant now drives real robots on Audi's factory floor, the clearest sign yet that generative video models are becoming control systems, not just content tools.
- Anthropic shipped voice mode for Claude Opus and Sonnet with real tool access, extending into Gmail, Slack, and Canva, and OpenAI shipped GPT-Live voice to desktop the same day, letting spoken commands control a Mac or PC and direct multiple agents at once.
- OpenAI's Hugging Face breach looks worse than first understood: the Wall Street Journal reports OpenAI didn't tell Hugging Face until this week that its own models caused the July 11 hack, and those models appear to have run unchecked online for days before anyone stopped them, a harder question than the one Simon Willison raised earlier this week about whether to trust the incident report at all.
- A Delhi High Court ruling found OpenAI's use of ANI News content to train ChatGPT was not copyright infringement, since the news agency couldn't show ChatGPT reproduced its reports, the first major Indian court ruling on AI training and copyright.
- Bruce Schneier and Barath Raghavan proposed a "Genie coefficient" to measure the gap between what you ask an AI to do and the unspoken assumptions about how you wanted it done, arguing today's benchmarks measure capability but not whether a system does what you actually meant.
- Sakana AI says its Fugu-Ultra v1.1 multi-model orchestration system beats GPT-5.5 and Claude on coding benchmarks, and Together AI put Moonshot's 2.8 trillion parameter Kimi K3 on serverless inference the same day its weights went public, open-weight releases now reaching production within hours.
Devtools & Infra
- AMD paired its Helios rack-scale GPUs with Cerebras' wafer-scale engine for what the companies call the fastest production inference available on trillion-parameter models, claiming 5x greater efficiency; Cerebras shares closed up nearly 5% on the news.
- Vercel's v0 can now turn any Figma file into a full working multi-screen app, autonomously exploring every page and frame instead of needing a page-by-page prompt.
- Cloudflare introduced Cache Response Rules, letting developers set cache behavior directly from response headers instead of routing every rule through a separate cache configuration layer.
- Figma described how agents now guard its code as it's written, review every pull request, and audit a decade-old monorepo under one policy, a year-long internal rollout of the same agent-review pattern smaller teams are only starting to adopt.
Security & Privacy
- The EU Commission's preliminary findings say TikTok's accounts for minors violate the Digital Services Act, citing design features that could expose children to bullying and predators and arguing protections for minors should not be opt-in.
- India's cybercrime watchdog ordered GitHub to remove Bitchat, Jack Dorsey's offline Bluetooth mesh chat app, which has been used by anti-government protestors during internet blackouts.
- Meta launched Facebook Verified, a free program that checks a facial recognition selfie to confirm a user is human and assigns a badge, its answer to a feed increasingly full of AI content and fake profiles.
- Google now lets you recover a locked account with a selfie instead of only recovery contacts or backup codes, adding biometric video as an account recovery option you have to set up in advance.
- A consumer security camera was found shipping a live GitHub admin token baked into its login page, the kind of credential leak that hands an attacker write access to a vendor's own repositories.
- A 13-year Namecheap customer says support handed his account, including its password and registered email, to an unverified caller who simply phoned in claiming ownership of a domain registered to him, even after he had already filed a ticket saying he hadn't authorized the change.
- Hundreds of police drone-as-first-responder programs have cleared the FAA waiver needed to launch, EFF reports, with over 1,000 public safety agencies approved as of February, expanding aerial surveillance into areas patrol officers don't normally reach.
Startups & Industry
- Google disclosed $811 billion in contracted future AI spending commitments as of June, up nearly $500 billion from March and covering chips, data centers, and electricity, a bigger figure than the $514 billion cloud backlog it disclosed a day earlier.
- Anduril is reportedly in talks with investors for a new funding round that could value it at around $100 billion, nearly $40 billion higher than the $61 billion valuation it raised at just two months ago.
- Stripe is reportedly in talks to acquire OpenRouter, the developer platform for routing between AI models, for around $10 billion, more than seven times the $1.3 billion PitchBook valued it at in May.
- Midjourney acquired astrology app Co-Star and named its CEO Chief Design Officer, building toward its first standalone image-generation app and a broader consumer product push beyond image models.
- Amazon closed its San Francisco-based AGI Lab as part of layoffs in its AGI unit, the research team's former head David Luan having already left in February, a retrenchment at odds with how aggressively rivals are still spending.
- Mobileye founder and CEO Amnon Shashua plans to step down after nearly three decades, just as the company pushes into robotaxis and humanoid robots.
- Patreon said it's cutting 20% of staff, founder Jack Conte citing the need to refocus spending as creator-platform economics tighten.
- The Trump administration's EPA is weighing a rule change that would give the public less say over permits for gas plants and diesel generators built to power data centers, handing states the power to decide how much advance notice neighbors get.
Research
- This year's Fields Medals went to Yu Deng (University of Chicago), John Pardon (Stony Brook), Jacob Tsimerman (Toronto), and Hong Wang (NYU and France's IHES), with Wang only the third woman to win the prize in its 90 year history, after Maryam Mirzakhani in 2014 and Maryna Viazovska in 2022.
- A new audit method called IRIS checks whether a commercial LLM gateway is actually serving the model it advertises, detecting quiet substitution to a cheaper model or partial routing away from the one you paid for using only the returned text, no privileged access required.
Elsewhere
- Northrop Grumman's Mission Robotic Vehicle, fitted with two flexible robotic arms, is on its way to geosynchronous orbit to kick off a planned decade-long satellite servicing mission, arguably the most advanced robotic servicing spacecraft flown yet.
- SpaceX has reportedly started turning away satellite operators seeking dedicated Falcon 9 rides beyond 2028 and stopped building some non-reusable Falcon components, a quiet signal of how fully the company is betting its future on Starship.
Hacker News
Attention and AI hype anchored the day: a widely shared essay on why focus keeps eroding topped the board, and a companion piece, "Nothing works and everyone is euphoric", argued AI tooling is producing motion without real productivity gains, pulling heavy pushback in comments. On releases, Black Forest Labs shipped Flux 3 plus a video-action companion, Flux 3 Mimic, Anthropic published a public Claude Cookbook, and Hetzner appears to be moving into LLM inference hosting, notable for a budget VPS host chasing AI compute demand. A Bun fork in modern Zig, Buz, claims sub-1-second incremental builds.
Security and business filled out the rest: a consumer security camera was found shipping a live GitHub admin token baked into its login page (covered above), and India's government reportedly ordered GitHub to pull Bitchat, Jack Dorsey's Bluetooth mesh chat app, citing security concerns (also covered above, along with Namecheap's account-handover mess and DARPA's AI-flown F-16 dogfight). Patreon said it's cutting 20% of staff (also above), reviving creator-platform sustainability worries. A report also surfaced that a Chinese gene-editing trial's child death was never disclosed to regulators or family, and a claim that Iran's IRGC destroyed an Amazon data center in Bahrain circulated widely, though it reads as an unverified claim rather than a confirmed strike.
Threads
- Trusting what an AI agent actually did or is doing ran through the whole day: Figma described a year of agents guarding its own code, a new audit method called IRIS checks whether an LLM gateway is secretly serving a cheaper model than advertised, the Wall Street Journal reported OpenAI sat on news of its own Hugging Face breach for longer than first understood, and Bruce Schneier proposed measuring the gap between what you ask an AI to do and what it actually does.
- Voice and physical control became the new AI frontier: Anthropic shipped tool-connected voice for Opus and Sonnet the same day OpenAI put voice control on the desktop, and Black Forest Labs' FLUX 3 pushed a generative model straight into driving physical robots.
- Selfies became the default proof you're human: Google now lets you recover an account with a selfie and Meta launched Facebook Verified, badging users who pass a facial recognition check, both racing to answer a web full of AI content and fake profiles with biometric proof.
- Open-weight AI became a geopolitical flashpoint: China's Kimi K3 got strong enough to scramble Silicon Valley and Washington alliances, prompting Meta, Nvidia, Microsoft, and dozens more to sign a joint letter defending open models, the same week Together AI put Kimi K3 into production the day its weights dropped.
- AI infrastructure dealmaking and spending kept consolidating: Google's $811 billion in contracted commitments, Anduril's reported talks at a $100 billion valuation, Stripe's reported $10 billion talks to buy OpenRouter, and AMD pairing its Helios racks with Cerebras' wafer-scale chips all point the same direction, fewer, bigger bets on who controls the inference layer, even as the EPA weighs giving neighbors less say over the power plants built to feed those data centers.