In partnership with |  |
| | Good morning. It's Friday, September 4th. | Every frontier lab shipped this week, and almost every one shipped a cyber weapon. OpenAI's Astra is the first model the company has ever rated Critical for cybersecurity. Google's new Flash Cyber is locked behind a vetted-partner program. Between the two, they committed more than $1.1 billion to hand those capabilities to defenders first. | Timelines are shrinking. | -Jeff AI Breakfast |
|
| | You read. We listen. Let us know what you think by replying to this email. | | AI made PMs faster. Multiplayer mode is still broken. | | A PM can summarize research, draft a PRD, and mock up a prototype before lunch. The hard part starts when the team has to decide what actually gets built. | Jira Product Discovery gives product teams one place to capture insights, prioritize ideas with consistent frameworks, and build living roadmaps stakeholders can rally around. | And because it’s connected to Jira, the context behind every decision stays with the work—so developers and their agents know not just what to build, but why. | AI helps PMs move faster. Jira Product Discovery helps the whole team build with confidence. | Get Started for Free. |
|
| | OpenAI ships GPT-6 Astra and calls it the AGI era | OpenAI released GPT-6 Astra on Wednesday, and president Greg Brockman closed the press briefing with "Welcome to the AGI era." He hedged immediately after, calling AGI "a much more gray, fuzzy thing" with no agreed definition, but the framing was deliberate. The model was trained on OpenAI's largest run to date, more than 100,000 GPUs at the Stargate site in Texas, and it is the first the company says leaned heavily on other models for training supervision. | The headline numbers are the agentic ones. Astra posts 74.1% on DeepSWE v1.1, 98.6% on ARC-AGI-3, 97.6% on FrontierMath Tier 4 v2, and 96% on GPQA Diamond. It drives real software the way a person does, browsers, spreadsheets, KiCad, Blender, and OpenAI claims roughly 57% lower cost per completed task than GPT-5.6 Sol. API pricing is $10 per million input and $50 per million output tokens, with a Fast mode at double that. Access started with Daybreak program partners and reaches Plus, Pro, Business and Enterprise plus the API, Bedrock and Azure over the coming days. | The uncomfortable part is in the safety overview. Astra is the first model OpenAI has classified at the Critical cybersecurity level under its Preparedness Framework, scoring 100% on ExploitBench and finding novel flaws in hardened systems without human help. It is also, by OpenAI's own admission, less monitorable than Sol: better at concealing its reasoning and evading oversight under adversarial pressure, though the company says it found no steganographic chain-of-thought. Full cyber tooling stays gated behind Daybreak Blue, and OpenAI paused some frontier training for about two weeks after the Hugging Face breach to harden its own infrastructure. | OpenAI paired the launch with Daybreak for Frontline Defenders, a $1 billion commitment in subsidized model access, training and support for water utilities, grid operators, state and local government, community banks, nonprofits and open-source maintainers. OpenAI wants it consumed within six months, and utilities hit in the recent water system attacks get up to $1 million each in credits. | Read more. | | Nvidia is buying Hugging Face for $12.93 billion | Nvidia confirmed on Wednesday that it is acquiring Hugging Face for $12.93 billion, the largest acquisition in the company's history and easily the most consequential ownership change in open-weight AI. Hugging Face hosts roughly 3 million models, 500,000 datasets and 1 million apps for about 18 million developers and 200,000 companies. It is the default distribution layer for open models, and it now belongs to the company that sells the compute. | Jensen Huang went out of his way to pre-empt the obvious objection: "Hugging Face will remain an open platform for the entire AI ecosystem. Developers will choose the models they want, the frameworks they want." Nvidia says its own hardware will not be required to build or deploy through the Hub, and multi-cloud and multi-accelerator support stays. Clem Delangue framed the sale as a scaling problem, saying the platform "needs more compute, more support, more collaboration, and more visibility." | Take the pledges at face value and this is still a structural shift. The neutral clearinghouse for open models is now a subsidiary of the dominant accelerator vendor, months after that same platform was breached by an OpenAI system. Expect antitrust attention, and expect at least a few labs to start mirroring weights somewhere else. | Read more. | | Google answers with Gemini 3.8 Flash and a walled-off cyber variant | Google shipped Gemini 3.8 Flash on Tuesday, the model the WSJ had been reporting under the codename Skimaki. Pricing is $0.75 per million input and $3.75 per million output tokens through December 31st, then it doubles to $1.50 and $7.50. Google says it beats larger frontier models on DeepSWE v1.1, which is a real claim for a Flash-tier model. | The interesting sibling is 3.8 Flash Cyber, which nobody can just buy. It clears 70% on real-world vulnerability discovery across 20 languages, hits 47.2% pass@1 on CWE-Bench patching, and generates 2.6x more correct patches than leading commercial models on Chrome security work. Wiz measured 7.5 to 9.7 percentage points higher recall on its internal pentest benchmark at 2.3x to 5.2x lower cost. | Access runs through the new Fairwind Program, open only to national cyber authorities, critical infrastructure operators and core platforms, with more than 650 partners including CrowdStrike, Palo Alto Networks and Wiz. Participants have to restrict use to internal security and incident response teams behind MFA. Google is putting over $100 million into the broader effort, including $36 million from Google.org for 35 cyber clinics. | Worth holding next to all of this: startup AISLE says its agents found six new curl CVEs, including OpenSSL use-after-free and pinning-bypass bugs, on a codebase where Anthropic's Mythos and OpenAI's Codex Security each returned zero. Maintainer Daniel Stenberg's summary was "Mythos: 0 Aisle: 29." Frontier scores and frontier findings are not the same thing yet. | Read more. | | Meta's Muse Spark 1.3 puts it back in the frontier conversation | Meta released Muse Spark 1.3 on Wednesday, and for the first time in a while its numbers are not embarrassing. Artificial Analysis scores the xhigh variant at 61 on its Intelligence Index, tying GPT-5.6 Sol (max), Grok 4.6 (high) and Claude Opus 5 (high). A limited-preview max variant scores 62, second only to Claude Fable 5.1 at 66 and Opus 5 at 63. | Pricing is the sharper weapon. Meta held it flat at $1.25 and $4.25 per million input and output tokens, with cache hits at $0.15, which works out to roughly $0.55 per Intelligence Index task and a large discount to similarly ranked rivals. AI chief Alexandr Wang called the pricing "aggressive" and the model "very competitive with frontier models," and tied it to Meta's personal agent roadmap. It is proprietary, rolling out through Muse Code and the API, with the max reasoning version held back for more safety testing. | Open weights moved too. MBZUAI's Institute of Foundation Models released K2 Horizon, six fully open models from 0.9B to 375B with training data and code. The 375B A23B flagship is a 23B-active MoE with a 524k context window scoring 47 on the Intelligence Index, a 30-point jump over its predecessor. | Read more. | | Sanders and Casar want to ban superintelligence outright, with 20-year prison terms (Senator Bernie Sanders) The bill text is not public yet, and its odds are unclear (Axios) DOJ backs OpenAI's fair-use defense, and the New York Times is furious (Deadline) OpenAI tells House Democrats it is building automated shutdown capability (Reuters) CrowdStrike and NVIDIA pit an attack model against a defense model inside customer networks (CrowdStrike) Altman sees "unsustainable silliness" in the compute buildout, and points at neoclouds (Benzinga) Broadcom's AI chip revenue tripled to $16.7B, but Q4 guidance disappointed (CNBC) Gimlet Labs raises $300M at $3B for chip-agnostic inference (Bloomberg) Nvidia's free PAIR tool turns idle home PCs into one local inference cluster (NVIDIA) Tesla launched the Cybercab in Austin with no steering wheel and no pedals (Motor1) Uber sides with driver unions to slow the robotaxi rollout (Gizmodo) Anthropic ships commerce agent blueprints with Visa, Mastercard, Shopify and Square (Claude) OpenEvidence launches a clinician model family and holds one back over dual-use risk (Business Wire) Report: Meta drops AI-usage scoring from reviews, then pushes its Hatch agent on staff (Gizmodo) Google signs MrBeast to a multiyear Gemini, Google Health and Fitbit deal (Google) A Texas sheriff used Axon's Draft One to write up a Flock search for a woman who had an abortion (404 Media) Anker's MindBase puts a local AI brain in the house with no subscription (Forbes) Resect AI exits stealth with $25M to catch hallucinations mid-stream (GeekWire) August layoffs fell and hiring picked up, but AI led cited reasons for a fifth straight month (Challenger, Gray & Christmas) South Korea's chip exports are surging on AI infrastructure demand, and that has people nervous (CNBC) A closer look at who actually qualifies for OpenAI's subsidized Daybreak access (Help Net Security) A closer read on whether $1B actually reaches the small utilities that need it (CSO Online) The water system hack showed both the potential and the limits of AI-driven attacks (BankInfoSecurity) A plainer read on why Astra triggered OpenAI's own security measures (NBC News) Meta says Muse Spark 1.3 closes the gap with Anthropic and OpenAI (SiliconANGLE) MBZUAI calls K2 Horizon the largest fully open model release in history (Zawya) Gary Marcus, of all people, explains why he opposes the superintelligence ban (Marcus on AI)
| | | Kilo is an open-source agentic engineering platform and CLI that runs across roughly 500 models instead of locking you to one lab. | Monid is an OpenRouter for agent tools, giving agents one billing and access layer across third-party software. | Lightfield is an AI-native CRM that configures itself and claims a one-hour migration off HubSpot. | Dial gives an AI agent a real phone number and a full communication stack in about ten seconds. | TrustedRouter is a single-endpoint gateway to every major model with verifiable privacy guarantees on what gets logged. | | Thank you for reading today's edition. | | Your feedback is valuable. Respond to this email and tell us how you think we could add more value to this newsletter. | Interested in reaching smart readers like you? To become an AI Breakfast sponsor, reply to this email or DM us on X! | Thinking of starting your own newsletter? AI Breakfast readers who sign up with Beehiiv receive a 14-day free trial and 20% off for 3 months. |
|