The day's tech, sifted: Jul 30, 2026
What matters today: Leopold Aschenbrenner's AI-focused hedge fund Situational Awareness sold off nearly all its public stock holdings to Ken Griffin's Citadel after a punishing tech selloff, the fund having grown to as big as $45B at the start of July before the losses hit; it still holds a $5B private stake in Anthropic and will keep running as a private investment firm. Google DeepMind shipped Gemini Robotics 2, folding several models into one system for full-body humanoid control, multi-finger dexterity, and multi-robot collaboration, a jump Wired frames as a step into "physical AGI". And Wiz disclosed a now-patched Azure CosmosDB flaw that would have let an attacker remotely compromise any of its users, Microsoft says with no evidence of customer impact, one more entry in a week already crowded with agent-security and infrastructure-hardening stories.
AI / LLMs
- Google DeepMind's Gemini Robotics 2 combines several AI models into one system to control humanoids and other robots, adding multi-finger dexterity and cross-robot collaboration; Wired calls it a significant jump into "physical AGI," with the risks that come with putting AI into the real world.
- Moonshot AI's Kimi K3 got a 256K-context checkpoint, and HN's own hands-on math pegs self-hosting it at roughly 20% more hardware cost for 20% better task resolution than API use: the self-hosting economics debate that started with K3's launch keeps sharpening.
- OpenAI president Greg Brockman confirmed the company is building a "family of devices" for its chatbots, declining to confirm the rumored 2027 smart speaker or a wearable, saying only "you can expect them soon."
- Mark Zuckerberg used Meta's Q2 earnings call to preview a vision for "personal agents" that work 24/7 on a user's behalf, pointing to coding as the first domain where agents have "really taken off."
Devtools & Infra
- MCP's protocol core is now stateless, dropping the session-ID dependency that tied requests to one server instance, a change Ars Technica calls the fix for the standard's main enterprise-adoption barrier; Vercel's mcp-handler already ships support for the new spec and the MCP TypeScript SDK v2.
- Cloudflare moved cdnjs, the open-source CDN behind roughly 12% of all websites, fully onto its own Developer Platform, serving 9 billion requests a day at a 98.6% cache hit rate after the migration surfaced and then fixed platform limits along the way.
- Figma's security team built an internal agent that triages alerts, investigates, and writes fixes, cutting alert time-to-resolution 71%, one more entrant in the agent-security wave rippling through the industry this week.
Security & Privacy
- Wiz found a since-patched flaw in Azure CosmosDB that would have let an attacker remotely compromise any of its users; Microsoft says it has seen no evidence the flaw was exploited before the fix shipped.
- HAWK, a post-quantum signature scheme, was withdrawn from NIST's third-round standardization after Anthropic's Mythos model found a flaw serious enough to break it, while a deep dive into Microsoft's "Project Glasswing" shows engineers still racing to patch bugs Mythos surfaces in Microsoft's own code faster than they can fix them.
- Perplexity open-sourced Numbat, a cross-harness layer that monitors and blocks dangerous agent behavior before it executes, built in direct response to last week's OpenAI agent breach of Hugging Face.
- The prosecution of Sam Tunick, the American charged over a GrapheneOS duress-wipe at the border, is moving forward: his lawyers confirm GrapheneOS was running on the phone, and the case turns on what rights apply at the border, where the government has long argued US soil doesn't fully count; GrapheneOS itself maintains the wipe feature is constitutionally protected.
Startups & Industry
- Leopold Aschenbrenner's Situational Awareness hedge fund sold the bulk of its stock portfolio to Citadel after the fund, which grew to as big as $45B at the start of July, took heavy losses in the recent tech selloff; it still holds a $5B stake in Anthropic and will keep operating as a private investment firm.
- Microsoft's Q4 capex rose 70% YoY to $41B even as Windows OEM and Xbox hardware revenue both declined, and Samsung's Q2 operating profit jumped 1,814% to roughly $61.46B on AI chip demand; Meta raised its 2026 capex outlook to $130B-$145B while free cash flow fell 91% YoY on $2.4B in legal charges and $1.18B in layoff severance.
- Amazon's Zoox won the NHTSA's first-ever US approval to charge for rides in a steering-wheel-free robotaxi, letting it deploy up to 2,500 vehicles a year through 2028 without traditional controls like a wheel or pedals.
- London-based Nscale agreed to acquire Anyscale, the AI-workload efficiency startup, for roughly $1.65B, and Scale AI hired former Google Cloud COO Francis deSouza as CEO, a year after founder Alexandr Wang left for Meta.
- The European Commission plans to designate ChatGPT and Roblox as "very large online platforms" under the DSA as soon as August, a classification that brings extra content-moderation and risk-assessment obligations.
- xAI is suing Minnesota's attorney general over its new "nudification" app law, the same week it's also suing Grok users it accuses of generating CSAM in an apparent bid to preempt its own liability; Musk had better luck elsewhere, quietly settling X's ad-boycott lawsuit against advertisers after once seeking jail time over it.
Research
- More than half of AI unicorns have never led a qualifying research paper or preprint, and OpenAI alone accounts for nearly 40% of all AI-startup paper citations despite employing roughly 4,500 people; only eight of its researchers have authored five or more papers.
- IBM announced three new results it says clearly demonstrate quantum advantage with verifiable trust, each using a different approach to catch errors and validate that a quantum computer's output is actually correct rather than noise.
Hacker News
Two regulatory stories carry real weight today. The EU Court's ruling that VPNs are "lawful technical tools" is a rare bright line in copyright enforcement, worth reading against Google's parallel move to expand Android age checks worldwide by year end, a rollout already drawing heavy pushback in the thread count alone. A third, quieter regulatory jab: noyb's GDPR complaint against dict.cc over "1,741 informed consents" collected with one click.
On the AI-industry side, Science's piece on frontier labs barely publishing research anymore pairs uncomfortably with the NYT's report that AI companies are now recruiting electricians and carpenters by the thousands to wire data centers, a labor story that says as much about the buildout's physical scale as any GPU benchmark. Claude's status page also logged a resolved, elevated-errors incident today. Elsewhere on the front page, already covered above: Kimi K3's 256k checkpoint and its self-hosting economics, Gemini Robotics 2, and Anthropic's cryptanalysis results. For lighter reading: Ron Gilbert has started production on Thimbleweed Park 2, and the GCC steering committee published a formal AI policy worth a look for anyone tracking AI in compiler toolchains. The front page also still carries Superlogical, the Vision Pro house, Keychron's mouse firmware, the AC retrofit, and CheapFoodMap from this morning.
Threads
- Anthropic exposure cuts every direction in AI finance right now: Situational Awareness sold off its public stock but is holding onto its $5B private Anthropic stake even as its own fund craters, the same week Microsoft's Anthropic investment posted a $3.2B gain.
- MCP had a three-day arc: Anthropic's stateless rewrite shipped Tuesday, Ars Technica gave it a full technical read today, and Vercel's tooling already supports the new spec, an unusually fast ecosystem turnaround for a protocol change.
- Agent security is now a defensive AND offensive story on the same day: Wiz disclosing a real Azure flaw, while Perplexity's Numbat, Onyx Security's raise, and Figma's in-house triage agent (all from this week) build the tooling to catch exactly that kind of thing.
- Physical AI had a regulatory and technical pincer this week: Gemini Robotics 2's "physical AGI" launch lands days after the FCC's foreign-robot import ban that turned out to sweep up Roombas too, and analysts are already sorting winners from losers among robot makers caught by the ban; two very different governments-and-machines stories converging on the same hardware category the same week Zoox got the NHTSA's own green light to charge for robotaxi rides.
- Sam Tunick's border-search prosecution keeps developing since we first named him on 2026-07-27: today's reporting details the constitutional argument at the center of the case rather than just the charge itself.