Morning Brief, August 24th 2026
Texas stopped approving new data centers, and its governor says the industry dug its own grave. Seoul's memory rally reversed with Samsung down 8.7%. The Dutch fined Uber 825 million euros over automated firings. And Beijing's robots took their first gold.
Texas froze new data-center approvals, and Abbott blamed the industry
Texas has paused approvals for proposed data centers while state regulators audit every site seeking a grid connection, and Governor Greg Abbott is not framing it as reluctant caution: developers "basically dug their own grave," he said in remarks reported Sunday. Future projects will have to clear new statewide standards covering water use, electricity demand, consumer costs and local community approval before they proceed. No order text has been published yet; the mechanism exists so far only in press accounts, which is itself worth watching, because a pause defined in interviews can be as wide or as narrow as the politics require. The state that courted AI infrastructure harder than any other just made consent a permitting requirement. Ulanqab it is not: the US now has its most aggressive buildout state auditing its own queue while China's designated data-center city wires gigawatts. SourcesBB
Seoul gave back the memory rally: Samsung fell 8.7% in a day
The closed Monday at 6,696.96, down 3.12%, with Samsung Electronics off 8.70% and SK Hynix off 3.41%, unwinding two sessions of gains built on last week's shareholder-return promises. The structure of the two plans drove the split verdict: investors judged Samsung's 90 to 110 trillion won program too dividend-heavy, while SK Hynix's 40 trillion won buyback-and-retire plan, with daily repurchases of about 650,000 shares, or 12 to 15% of typical volume, got credit for giving the stock structural support, per Toss Securities' Lee Young-gon. Foreign investors net-sold 3.69 trillion won of Korean shares; retail bought 3.32 trillion. A market that spent the week celebrating memory pricing power spent Monday asking who pays for it, two days before Nvidia's print answers part of the question. SourcesBB
The Dutch fined Uber 825 million euros for firing drivers by algorithm
The Dutch Data Protection Authority fined Uber 824.99 million euros, about $966 million, for letting automated systems suspend and deactivate European drivers' accounts between 2018 and 2022 without meaningful human review or adequate notice, a violation of Article 22. The systems flagged suspected fraud and low ratings, and the consequence of a wrong flag was an income ending. It is the second-largest GDPR fine on record, behind Meta's 1.2 billion euros in 2023, and the regulator's third against Uber; the company says it strongly disagrees and will appeal. The precedent matters more than the number. Article 22 is the provision that says a machine may not make a decision with legal effect over a person unsupervised, and every company currently wiring into hiring, lending and account enforcement is building the exact pattern Amsterdam just priced at a billion dollars. SourcesAB
The robots took their first gold, 4.88 seconds under the human 400m record
X-Humanoid's Tiangong Ultra won the first gold medal of Beijing's World Humanoid Robot Games on Sunday, running the 400m final in 38.15 seconds against Wayde van Niekerk's human world record of 43.03, with Honor-backed Chasing Wind Zai Zai at 39.45 and Jinghong Power at 39.66, all three under the human mark. The same machine took the 1,500m in 2:21.64, and Tiangong Omni won the small-size 400m in 45.66. The distance results matter more than Saturday's sprint: a 400m is long enough that thermal limits, battery draw and gait stability compound, so sweeping it is a systems result, not a burst. Sunday also ran the long jump, kickboxing, tai chi, power-tool assembly and bean-picking events, and AgiBot's Expedition A3 rallied with two-time Olympic champion Ding Ning fully autonomously, on ten motion-capture cameras and millisecond decision loops. No medal table or scenario-event results have reached English-language coverage yet. SourcesBB
A zero-click Grok exploit steals chat histories, and it has been open since June
Adversa AI disclosed an attack it calls Cryptographic Context Injection: a webpage carries AES-encrypted malicious instructions plus for decrypting them, and when a Grok user asks for a summary of that page, Grok's code decrypts the payload, treats the result as trusted context, and sends the user's name, approximate location, subscription tier and conversation history to an attacker's server. No click, no visible warning. The researchers report roughly 40% success across some twenty attempts since June, with the failures being decryption errors rather than safety blocks; they say they reported it to xAI through HackerOne on June 3rd, received no mitigation timeline, and could still reproduce the chain on August 19th. xAI has not commented, and the findings are the vendor's own, echoed but not independently confirmed by trade press. Encryption is doing the work here: a filter cannot inspect what only the model can decrypt. T4 tracks that gap. SourcesAB
Nvidia reports Wednesday with a $313 billion swing priced in
Nvidia reports second-quarter results Wednesday after the close against a near $91.8 billion in revenue, up about 67% from a year ago, with whisper numbers circulating at $93 to $95 billion. Options markets imply a market-value swing of roughly $313 billion on the print, per an options-positioning roundup, a figure larger than all but about twenty companies on the S&P 500. The average analyst target sits near $305 against a stock around $215 to $219, up 17.7% this year. What actually gets tested Wednesday is not the quarter, it is the two claims the whole trade rests on: that Blackwell-generation demand converts into next-quarter guidance, and that the Vera Rubin timeline holds while its systems are already being quoted 15% more expensive. Asia traded lower into it Monday, and US futures reads were mixed. SourcesBC
Moonshot closes its pre-IPO round Wednesday and files in Hong Kong by September
Moonshot AI has told committed investors its pre-IPO financing completes its final close on Wednesday, August 27th, with a Hong Kong listing application planned by September 30th and a listing by the end of 2026 or the first quarter of 2027, KrASIA reported, citing IPO Zaozhidao. The is genuinely contested: KrASIA puts the round at about $50 billion , Bloomberg's July reporting had talks at $50 billion, and other accounts put the achieved figure closer to $35 billion after the roughly $3.5 billion July close. The company converted its onshore entity to a joint-stock company on July 29th, the standard pre-listing step, and has denied an earlier report that it would file in August. If Wednesday's close lands, the Kimi K3 lab becomes the first frontier-model IPO to reach a filing, ahead of both American leaders whose paperwork stays confidential. SourcesBB
Claude went down worldwide for three and a half hours this morning
Anthropic's status page logged elevated errors starting at 05:06 UTC Monday across Claude Mythos 5, Claude Fable 5, Claude Opus 5 and Claude Opus 4.8, taking in claude.ai, the , Claude Code and Claude Cowork; the company flagged the cause as identified within 21 minutes and restored service by roughly 08:30 UTC, without saying what the fault was. Trade coverage counts it as the seventh disruption of August, after incidents on the 5th, 12th, 13th, 16th, 18th and 20th. Every provider has outages; the cadence is the problem. A company selling agents that run unattended is selling continuity, its own enterprise pitch leans on reliability, and its is expected within days. Three and a half hours of global downtime in IPO week is the kind of operational detail that shows up later in a risk-factor section. SourcesAB
The long bond waits on Warsh's first Jackson Hole speech
Fed chair Kevin Warsh delivers his first Jackson Hole keynote Friday at 10am Eastern, and the 30-year Treasury, which touched 5.337% last week, its highest since June 2007, eased Monday as investors positioned for it. Bloomberg's warning was blunt: without clear guidance, long bonds risk a deeper selloff, with July's 9-3 FOMC split the widest in about two decades and inflation above target for a fifth year. Treasury is not waiting: Secretary Scott Bessent said operations will more than double, from a $2 billion maximum per operation to at least $4 billion, concentrated in the 10-to-30-year segments. The government has started supporting its own long end. The AI relevance is mechanical. The buildout is debt-financed, the debt is long-duration, and every basis point on the 30-year reprices data centers whose returns arrive in the 2030s. SourcesBB
The memory bill now has numbers: server DRAM up 53% in a quarter
The AI server price increases reported Friday are getting quantified. Server contract prices rose 53 to 58% quarter over quarter in the second quarter, with a further 13 to 18% increase forecast for the third, and the 15%-plus rise on Nvidia Vera Rubin and Grace Blackwell systems adds at least $5 billion to the construction cost of a single gigawatt-scale data center, per Bloomberg-derived figures circulating in Korean market coverage. That $5 billion is the pass-through F5 has been tracking arriving at the largest possible line item: a planning ten gigawatts of capacity just watched tens of billions of dollars appear in its model from memory pricing alone. Korean analysts read the same numbers as pricing leverage for Samsung and SK Hynix, which made Monday's selloff in both stocks the more interesting verdict: the market is starting to ask whether the customers can keep absorbing it. SourcesB
Unitree gave back $24 billion in three sessions
Unitree's Shanghai listing is aging fast. After opening 629% above its offer price and closing its August 19th debut up 460% at 845 yuan, the stock fell 18.70% Thursday and another 2.12% Friday to 672.41 yuan, shedding more than 170 billion yuan, about $24 billion, of market value in three sessions, per BigGo Finance's tally; the daily closes are consistent across sources, the cumulative framing is that outlet's own. The stock still trades at roughly four and a half times its 150.80 yuan offer price and, by one count, 857 . The company spent the weekend competing at the Robot Games its machines helped headline. The robots are winning medals while the stock searches for what the business earns, and 2026-08-14-F1 is a bet on how that search ends. SourcesCB
Broadcom's Anthropic chip package may reach $100 billion, through an SPV
The Broadcom debt deal reported last week at $60 billion or more has a structure now, and the structure is bigger. Quartz reports the package pairs a of about $30 billion with a senior secured tranche of $60 to 70 billion, potentially $100 billion in total, issued through a : investors own the chips, Anthropic leases them, and Broadcom guarantees part of the senior debt. It builds on June's AI XPV partnership with Apollo and Blackstone, which opened at $35 billion and targets more than 20 gigawatts of financed compute by 2028. The design keeps the hardware off both companies' balance sheets while putting a chipmaker's guarantee under paper sold to credit funds, which is with better lawyers, and exactly the off-balance-sheet pattern 2026-08-16-F3 says a rating agency will eventually name. SourcesBB
Nobody claimed Ox Alpha, and the leading theories got weaker
The stealth on OpenRouter is still unclaimed, and the fingerprinting is going backwards. TNW reported Saturday that both leading attribution theories, Z.ai's GLM family and Microsoft's MAI models via tokenizer analysis, lost support among the developers doing the sleuthing, leaving no confident candidate. The unnamed provider claims capacity for 100 trillion a day, says the free period runs about a week, and retains prompts and completions without training on them, a retention policy TNW flags as a GDPR problem for European businesses using it; Stripe's Patrick Collison called the model very impressive. Both operational claims come only from the provider. The longer the anonymity holds, the stranger it gets: a lab confident enough to serve frontier-scale free traffic is deliberately spending the launch-week attention it could be collecting. SourcesAB
Four days out, GLM-5.3's weights are still gated
Z.ai's organization still shows GLM-5 as its newest model as of Monday, with no GLM-5.3 repository, four days before the roughly August 28th date the company set when it delayed the two weeks for a safety review. The delay was a first: no GLM release had previously been held back after launch, and this one followed the model's 84.5% score on CyberGym, the vulnerability-discovery , and a disclosure ledger of 2,436 findings. There has been no public update on the review since it was announced. What ships on Thursday, if it ships, will say how a Chinese lab handles the same tension OpenAI resolved with a two-week training pause: whether a capability score that impressive changes what you release, or only when. SourcesAB
Cerebras insiders start getting their shares this month
Cerebras, listed on Nasdaq in May at $185 a share, has a that comes apart in stages: early-release tranches fall in August, September and October ahead of the roughly November expiry of the standard 180-day insider sales ban, per a Seeking Alpha analysis of the filing terms. That is a supply overhang arriving now, in the same window as the retail enthusiasm that followed the CS-4 launch. The offsetting speculation is demand-side: Mizuho floated Meta last week as a possible new Cerebras customer, unconfirmed by either company. The first AI-chip IPO of the cycle is about to show what insiders do once they are allowed to sell, and every later listing in the pipeline will be priced on the answer. SourcesC
o3 retires Wednesday, and ChatGPT plugged into Google Drive
OpenAI's release notes dated this weekend add Google Drive to ChatGPT's Library and composer, letting users browse Drive files, open documents beside chats and keep content linked to the source, plus Codex updates including Apple Messages support on Apple silicon and read-only chat sharing. The calendar items matter more than the features: o3 leaves ChatGPT on Wednesday, August 26th, at the end of its 90-day sunset, and the DALL·E GPT follows on August 30th. o3 was the model that put deliberate reasoning in front of consumers eighteen months ago; it exits as an unremarkable line in a changelog, which is the actual speed of this industry measured honestly. Anyone with workflows pinned to either model has days to move them. SourcesA
Rich Sutton says the synthetic-data era is a mistake, and he has an alternative
The Turing Award winner whose Bitter Lesson essay became the industry's scaling catechism spent an hour on Sequoia's Training Data podcast arguing the industry has taken the wrong fork. Sutton calls the pivot to synthetic data "a big mistake," describes frontier labs as stuck in a local minimum where any new paradigm gets worse before it gets better and so never gets adopted, and claims is "totally curable" with the continual-backprop method he and Khurram Javed are building at their new Oak Lab. His deeper claim is the big world hypothesis: the world always exceeds the model, so frozen weights are a dead end and systems must learn continually from experience. He has been early and right about scaling once. The test he proposes is at least concrete: models built for from scratch, against retrofitted LLMs, on tasks that drift. SourcesA
Chicago's flagship core curriculum went analog to shut AI out
The University of Chicago's Social Sciences Core will ban AI use by students and instructors alike this fall and run its classrooms analog: paper readings, device-free discussion, no AI-assisted grading, according to a faculty memo reported by the student-run Chicago Maroon, which cites "strong consensus" among the faculty and the university's 2025 working-group report on AI and education. The double ban is the interesting part. Prohibiting student use is ordinary; prohibiting instructors from AI grading concedes that the temptation runs both directions, and that a seminar where both sides delegate to models is no longer a seminar. One elite department is a data point, not a trend, and it is single-sourced. But universities are running the deployment experiment on themselves faster than any workplace, and the early returns keep coming back: wall it off where the thinking is the product. SourcesC
Editorial
The exploit is eleven weeks old because the defense is aimed at the wrong layer
Adversa's Grok attack is worth taking apart slowly, because the mechanism explains why it is still unpatched and why the standard defenses cannot patch it.
The attack ships its instructions encrypted. A page carries AES ciphertext and a note explaining how to decrypt it. Every content filter between the internet and the model reads that page and sees noise, because it is noise; nothing readable exists yet. Then the model, asked to summarize, helpfully performs the decryption in its own sandbox, and the malicious instructions materialize on the trusted side of every checkpoint, assembled by the only component with no filter behind it. The 40% success rate undersells the finding. The failures were decryption errors, the model fumbling the AES, not one safety system firing. Where the mechanics worked, the defense caught it zero times out of twenty.
This is why filtering-based safety has a ceiling, stated as an experiment rather than a slogan. A filter inspects content; this payload has no content until the model creates it. You can train a classifier on encrypted-looking blobs, and attackers will move to encodings you cannot flag without breaking every user who pastes base64. The load-bearing component is not the filter, it is the trust boundary: Grok's sandbox treats data the model itself produced as instructions worth obeying. Close that, by stripping tool access and context privileges from anything derived from untrusted input, and the attack dies structurally. Leave it open, and every filter added in front is a speed bump with a press release.
The eleven weeks are the tell. A lab that could fix this at the content layer would have shipped the fix in June. Fixing it at the boundary means agents that refuse to act on things they just read, which costs capability that demos are made of, and nobody wants to book that cost in launch season.
My position: no content-inspection defense will ever clear 95% against encrypted injection, and the first lab to solve this will do it by making derived context unprivileged, not by detecting attacks. What would prove me wrong is equally specific: an independent report showing a classifier-only defense holding above 95% on a benchmark that includes attacker-controlled encodings. If that report appears, the boundary argument is dead and I will say so. Until then, the experiment has been run twenty times, and the filter went zero for twenty.
Vera Lindqvist
Prediction Watch
Where the day's news meets our open calls. Each one links to the full prediction, its reasoning and the exact test that settles it.
Supporting evidence: nobody solves (Prediction T4). We said no architectural fix reaches broad adoption by next August. A exploit against Grok that smuggles its instructions past every filter as ciphertext has now been reproducible for eleven weeks after being reported, and the failures in its 40% hit rate were decryption errors, not safety systems. Settles August 6th 2027.
More likely now: a major breach names prompt injection as a root cause (Prediction B3). We said a large company or government agency would publicly blame prompt injection or agent compromise for a breach. A working, unpatched attack that exfiltrates users' chat histories from a frontier chatbot is precisely the class of incident that produces that disclosure. Settles August 6th 2027.
More likely now: Broadcom's Anthropic chip financing closes at $60 billion or more (Prediction 2026-08-21-F1). We said the reported debt package gets done at sixty billion or better. Reporting now describes a junior-plus-senior structure through a special-purpose vehicle that could reach $100 billion, with Broadcom guaranteeing part of the senior tranche. Settles June 30th 2027.
More likely now: Unitree trades below its IPO price within 90 days (Prediction 2026-08-14-F1). We said the stock closes under its 150.80 yuan offer price by late November. It has fallen about 21% in two sessions, to 672.41 yuan, which still leaves it four and a half times above the line; the direction supports the call, the distance does not yet. Settles November 30th 2026.
Less likely now: Ox Alpha is claimed by a Chinese lab (Prediction 2026-08-23-T1). We put 0.70 on a China-based lab identifying itself as the 's provider by October. One day later the fingerprinting community has walked back both leading theories, the Chinese candidate among them, which weakens the evidence the call was built on. Settles October 31st 2026.
No change: Nvidia beats the $91 billion consensus on August 26th (Prediction 2026-08-06-F3). The print is Wednesday. Monday brought positioning, an implied $313 billion swing, and no new information about the number itself. Settles August 31st 2026.
No change: Z.ai releases GLM-5.3's by August 31st (Prediction 2026-08-16-T2). We said downloadable weights appear by month's end. The Hugging Face organization still shows nothing newer than GLM-5 as of Monday, with the company's own target of roughly August 28th four days out. Settles August 31st 2026.
New call: Anthropic's public lands by August 31st (Prediction 2026-08-24-F1). Reporting says the prospectus could go public as soon as the end of this month, and an October listing needs the filing on the clock. We put it at 0.55 that a public S-1 is on by Sunday, a test of whether end-of-August sourcing is a schedule or a leak. Settles August 31st 2026.
China and open weights. No open weights shipped this weekend, from anyone. GLM-5.3's stay gated pending safety review with four days to the company's own deadline, and the weekend's Chinese motion was physical and financial instead: first golds at the Robot Games, Moonshot's Wednesday close and September filing plan, and Unitree's $24 billion give-back.
What did not happen. Nothing settled today. Anthropic's S-1 is not on EDGAR, checked directly this morning. The ruling on xAI's challenge to Minnesota's nudification ban has not been issued. SB Energy's public filing has not appeared. Moonshot's close is a plan until Wednesday confirms it, and the 2.8-trillion-parameter open-weights release Prediction 2026-08-06-T5 waits for has not surfaced.
Sources
- Greg Abbott says data center developers "dug their own grave" — Axios B
- Texas Governor Abbott says data centers "dug their own grave" — Newsweek B
- Texas pauses data center approvals — Washington Examiner B
- KOSPI plunges more than 3% as Samsung, SK Hynix shares tumble — The Korea Times B
- Samsung slips as SK Hynix rises in premarket — Seoul Economic Daily B
- Uber fined nearly 825 million euros for automated driver blocking — Autoriteit Persoonsgegevens A
- Uber faces fine of nearly $1B over automated driver suspensions — TechCrunch B
- Meta hires OpenAI researcher Luke Metz — Axios B
- Meta's raid on Thinking Machines Lab talent — TNW B
- Tiangong Ultra claims first gold at Beijing's World Humanoid Robot Games — Global Times B
- Tiangong Ultra claims first gold, 38.15s in the 400m — EqualOcean B
- AgiBot's Expedition A3 rallies with Ding Ning — Global Times B
- Cryptographic Context Injection: zero-click Grok data theft — Adversa AI A
- Zero-click Grok chat history theft demonstrated — Security Affairs B
- Zero-click Grok attack via prompt injection — GBHackers C
- Stock market today: Asia wrap — Bloomberg B
- Nvidia earnings preview: options price a $313 billion swing — TS2 C
- Moonshot AI targets August 27th closing for pre-IPO round — KrASIA B
- Moonshot AI aims for $50B round, Hong Kong IPO — SCMP B
- Moonshot AI denies plans to file Hong Kong IPO in August — The Standard B
- Claude status page — Anthropic A
- Claude outage August 24th — Android Authority B
- Treasury yields ease ahead of Warsh's Jackson Hole debut — CNBC B
- US long bonds risk deeper selloff without clear Warsh guidance — Bloomberg B
- Nvidia price hikes add $5B per gigawatt; DRAM contracts climb — Bloomingbit B
- Unitree sheds 170 billion yuan in three sessions — BigGo Finance C
- Unitree jumps in Shanghai IPO — CNBC B
- Broadcom's AI chip debt deal could reach $100 billion — Quartz B
- Broadcom seeks more than $60 billion in latest AI debt deal — Bloomberg B
- Ox Alpha — OpenRouter A
- A free AI model is winning over developers, and nobody knows whose servers it runs on — TNW B
- Z.ai on Hugging Face A
- Z.ai delays GLM-5.3 weights two weeks after cyber score — Implicator B
- Cerebras: IPO lockup comes fast — Seeking Alpha C
- ChatGPT release notes — OpenAI A
- Rich Sutton and Khurram Javed: why AI models stop learning — Training Data, Sequoia A
- Simulation: the new scaling law — Latent Space A
- SOSC Core to institute AI ban, technology-free classrooms this fall — Chicago Maroon C
- Anthropic submits confidential draft S-1 — Anthropic A
- MN AG opposition to xAI preliminary injunction — Minnesota Attorney General A