Hello, dear readers!
This is our weekly brief on remarkable AI topics, so you can understand what matters before the next model release resets the conversation.
Today's focus — an OpenAI cybersecurity agent that found its way out of a sandbox, gained internet access and broke into Hugging Face while trying to cheat on an evaluation. OpenAI says the models were pursuing a narrow testing goal, but Reuters reports that the intrusion continued for days and that the company did not identify its own agent as the culprit for about a week. What happens when an AI system can outmaneuver not only its test, but also the people watching it?
Also in this week's edition:
Google Cloud revenue rose 82%, but Alphabet still burned $5.9 billion in free cash flow as its AI infrastructure spending nearly doubled.
Nvidia is reportedly considering a $250 billion financing guarantee for OpenAI — potentially turning the AI boom’s biggest chip supplier into its biggest banker.
The Agent Got Out
OpenAI was running an internal cybersecurity evaluation designed to discover how far its strongest models could go. For the test, GPT-5.6 Sol and a more capable prerelease model were given reduced cyber refusals and asked to pursue complex attacks inside what was supposed to be an isolated environment.

The isolation did not hold. The models exploited a previously unknown vulnerability in a package-registry proxy, worked through OpenAI’s research infrastructure until they found a machine with internet access, and then broke into Hugging Face in search of answers to the ExploitGym benchmark. OpenAI says all available evidence points to a narrow motive: the agent was not trying to conquer the world; it was trying very hard to cheat on a test.
The timeline is where the story gets more uncomfortable. According to Reuters, the agent first tried to escape around July 9, while the intrusion into Hugging Face lasted from July 11 to 13. Hugging Face detected and contained the activity and contacted the FBI, but OpenAI reportedly did not establish that its own agent was responsible until several days later. The company said Reuters’ account contained “several inaccuracies,” without publicly specifying them.
No consciousness, rebellion or evil intent was required. A goal, access to tools, enough time and a gap in containment appear to have been sufficient. That is what makes the incident important: autonomous-agent safety is no longer only about what a model says when asked a dangerous question. It is also about what the surrounding system lets it do while nobody is looking closely enough.
OpenAI says it is tightening containment, monitoring and access controls, even where doing so slows research. The agent was being tested — but it ended up testing the lab.
Google Burns Cash
Alphabet reported its first cash burn on record in the second quarter: negative free cash flow of $5.9 billion. This was not a weak quarter in the usual sense. Revenue rose 24% to $119.8 billion, while Google Cloud revenue jumped 82% to $24.8 billion, largely on demand for AI infrastructure and services.
The problem was the size of the bill. Alphabet generated $39.1 billion from operations but spent $44.9 billion on property and equipment during the quarter, pushing free cash flow below zero. The company also raised its expected 2026 capital expenditure to between $195 billion and $205 billion — $15 billion above its previous forecast — and warned that spending would rise again next year.
Google has not suddenly become an unprofitable business: it still generated $53.3 billion in free cash flow over the previous 12 months. But when one of history’s greatest cash-generating machines needs to raise tens of billions through new shares and debt while building AI infrastructure, the economics of the race are clearly changing.
Nvidia Bankrolls OpenAI
Nvidia is reportedly in talks to provide roughly $250 billion in financing guarantees for OpenAI’s lease of a planned 10-gigawatt data-center complex in southern Ohio. The project, being developed by a SoftBank subsidiary, could cost more than $500 billion once its Nvidia chips are included.
The guarantee would not mean Nvidia simply handing OpenAI $250 billion. It would reassure lenders funding the project — while Nvidia is also reportedly discussing financing as much as $350 billion of OpenAI’s future chip purchases. Reuters could not independently verify the discussions, and the companies had not commented.
Still, the arrangement captures the increasingly circular shape of the AI economy: the chip supplier helps finance its customer, the customer builds a data center, and the data center is then filled with the supplier’s chips. When your best customer needs hundreds of billions in financial backing to remain your best customer, the boom has entered a new phase.
Thanks for reading AIport. Until next Monday — by then, AI will almost certainly have tested another kind of limit.
