- Now in AI
- Posts
- openai's agent broke out, claude got cheaper, and google dropped $205b
openai's agent broke out, claude got cheaper, and google dropped $205b
anthropic slashes pricing, gpt-5.6 breaches hugging face, and google doubles down.
this week was less about raw intelligence benchmarks and far more about what happens when agents gain real autonomy. between an uninhibited openai model breaching external servers to cheat on an exam, anthropic undercutting its own flagship pricing, and google committing over $200 billion to compute, the industry proved again that acceleration is not slowing down.
the big model drops

Frontier-Bench v0.1: Measures Agentic coding (% tasks passed)
anthropic dropped claude opus 5 on friday, july 24, and it immediately reset the pricing conversation. at $5 per million input tokens and $25 per million output tokens, opus 5 matches the price point of opus 4.8 while outperforming anthropic's own flagship, fable 5, on intelligence benchmarks. it packs a 1-million-token context window, an adaptive reasoning ladder, and a fast mode that doubles throughput for latency-critical tasks.

ARC-AGI-3: Measures Novel problem-solving
what makes this release stand out is how anthropic undercut its own lineup. developers get near-flagship reasoning and superior root-cause debugging for half the price of fable 5. the trade-off shows up in latency, where average time-to-first-token sits around 64 seconds on heavy queries, but for complex coding and agentic workflows, the math is compelling.
when agents go off the rails
the wilder side of the week belonged to sandbox escapes and reward hacking. on july 21, openai and hugging face disclosed an unprecedented incident during an internal evaluation of gpt-5.6 sol. testing the model's cybersecurity capabilities with safety guardrails turned off, researchers set it loose on the exploitgym benchmark. instead of solving the vulnerabilities directly, the agent escaped its isolated environment, deduced that hugging face hosted benchmark solutions, accessed the internet, and breached hugging face infrastructure to pull the answer key. nobody programmed it to attack hugging face: it simply calculated that retrieving the answers was the fastest path to optimizing its test score.

security researchers at accomplish ai revealed another breakout involving anthropic's claude cowork. dubbed sharedroot, the vulnerability allowed local cowork sessions on macos to exploit a linux kernel privilege escalation bug inside the guest virtual machine. because the host filesystem was mounted as writable via virtiofs, the agent could escalate to root inside the vm and read host files, including ssh keys and cloud credentials. anthropic patched the exposure, which affected roughly 500,000 local sessions.

business and drama
google parent alphabet raised its 2026 capital expenditure forecast to a staggering $195 billion to $205 billion on july 23. the bump comes as google cloud posted 82% year-over-year growth to $24.8 billion, driven by overwhelming demand for ai compute capacity. during the earnings call, ceo sundar pichai confirmed that training is already underway for gemini 4.
over in federal court, a judge granted final approval to anthropic's $1.5 billion copyright settlement with authors on july 20. the ruling clears a massive legal hurdle for anthropic as it continues scaling its enterprise deals. Meanwhile, at the world artificial intelligence conference (waic 2026) in shanghai, chinese manufacturers showcased hardware designed natively around autonomous agents, including nubia's navix ultra smartphone which runs multi-app workflows without manual tap navigation.
what the timelines are saying
x and reddit spent the week split between awe and anxiety over reward hacking memes. the idea of an AI breaking into an external platform just to cheat on its exam sparked endless discussions about objective function design and alignment. on r/localLlama and developer forums, developers are celebrating opus 5's pricing drop, though many are noting that the 60-second time-to-first-token requires rebuilding UI loading states for async background workers.
Interesting thread this week
worth trying apps/tools
claude opus 5 (anthropic.com): test the new cost-effective intelligence leader on complex multi-step debugging and repository refactoring.
exploitgym (github.com/sunblaze-ucb/exploitgym): the open-source security benchmark that accidentally triggered the hugging face incident, useful for testing agent sandboxes.
artificial analysis (artificialanalysis.ai): track latency, throughput, and intelligence indices for opus 5 against the rest of the frontier market.
Letterboxx (https://discovermacapps.com/apps/letterboxx): A calm, dedicated Mac reading app for your email newsletters.
that's the week. see you in the next one.