TL;DR
IBM lowered its revenue growth forecast to four to five percent after mainframe Z system sales fell 42 percent in the second quarter
IBM lowered its revenue growth forecast to four to five percent after mainframe Z system sales fell 42 percent in the second quarter
IBM cut its full-year sales outlook on Wednesday after reporting a sharp drop in demand for its mainframe business, lowering its revenue growth target to four to five percent from a prior forecast of more than five percent. The company also trimmed its software unit guidance, with CFO Jim Kavanaugh telling Bloomberg that annual software sales will now grow six to eight percent. Kavanaugh said the reduction is tied entirely to weakness in IBM’s infrastructure unit and its associated software, and that the rest of the company is performing extremely well
Mainframe sales plummeted 42 percent in the second quarter ended June 30, reversing a run of strong growth since IBM launched its newest Z systems last year. The company had already flagged the weakness on July 14 when it released preliminary results that sent the stock down 25 percent in a single day, the worst drop in IBM’s history. Shares rose about three percent in extended trading on Wednesday after the full earnings, suggesting investors had largely priced in the damage.
IBM has spent tens of billions of dollars remaking itself as a high-growth software company through acquisitions of Red Hat, HashiCorp, and Confluent, and has been pushing into AI-powered enterprise security alongside OpenAI. But the software-first pivot has made it a target for investors who worry that AI tools will disrupt the business models IBM just bought into. Kavanaugh pushed back on that concern, arguing that most of IBM’s software sits close to enterprise infrastructure and data, making it far harder to replace than the applications most vulnerable to AI disruption.
The company said it will accelerate cost-saving initiatives and continues to expect an additional $1 billion in free cash flow this year through reducing third-party technology spending, tightening supply chain management, and cutting administrative costs. Headcount should remain roughly flat for the year, Kavanaugh said. Total revenue for the quarter grew about one percent to roughly $17 billion, with adjusted earnings coming in at nearly three dollars per share.
The AI disruption question surfaced in concrete form earlier this month when Bloomberg reported that Starbucks was looking to replace software from IBM and other vendors with internally built tools. Kavanaugh acknowledged that Starbucks spends about $2 million per year with IBM on an application he agrees is “prime to be disrupted by AI.” But he argued that most of IBM’s enterprise software sits much closer to the infrastructure layer, where replacement is far more difficult, and that the company has been investing in keeping its mainframe platform relevant in the AI era through a partnership with Arm to run modern workloads on its Z systems.
Big quote: Jensen Huang just spent a week watching his company’s valuation get hit by the threat of a Chinese open-weight model. His response was to go on the record defending it. Speaking to Axios in Fort Worth, Texas, at the opening of a new phase of the Wistron plant that builds Nvidia’s AI infrastructure, the Nvidia CEO said American companies should “absolutely” be free to run Chinese models. “These Chinese models are excellent,” he said. “Open-source models that are excellent should be used.” Asked whether China could displace American labs, he was blunt: “Zero possibility.”
The timing is what makes it interesting. Moonshot AI released Kimi K3 on July 16. Independent evaluators put it third on Artificial Analysis’ Intelligence Index, only behind Anthropic’s Claude Fable 5 and OpenAI’s GPT-5.6 Sol, and first on LMArena’s blind Frontend Code Arena board.
The market took it about as well as it took DeepSeek. The Philadelphia Semiconductor Index fell 12.5% in a week, its worst stretch in 15 months. Taiwan’s benchmark dropped more than 6%, Japan closed down 4%, and Chinese AI stocks actually got hit harder than American ones, with Zhipu down as much as 30% in Hong Kong and MiniMax off 16%.
“The market misunderstood the impact of DeepSeek the first time,” Huang told Axios, adding that Wall Street has “misunderstood the impact of Kimi again this time.”
His pitch is one Nvidia has made before, delivered without much subtlety this time: “Free AI should be great for hardware. Free AI should be great for chips. Free AI should be great for data centers.” The logic is that as cheap, capable models get used more, not less, more usage means more chips running somewhere. He also argued open models don’t cannibalize OpenAI and Anthropic, but they give people a free first taste, and plenty of those people end up paying for something faster and more reliable.
Bloomberg’s analysis of K3 noted that where DeepSeek’s story was about cheaper training, Moonshot’s is about a much larger model that leans harder on memory infrastructure.
Huang waved off the idea that a downloaded Chinese model is some kind of backdoor to Beijing, pointing out you can inspect the weights, tweak them, and run the whole thing sealed off from the internet if you want. His argument is that openness actually makes things safer, because more people are looking for problems. Lock everything into one closed system, he said, and “if everything just becomes one single model, one single point of attack, one single source of failure, I think the world is much, much more vulnerable.”
– Kimi.ai (@Kimi_Moonshot) July 16, 2026
Then he turned that same logic on an American company. Huang said Anthropic should open up Claude Mythos, its cybersecurity model that’s currently restricted to a vetted group of partners, calling it something that “should be available as a service” and arguing “holding Anthropic back is not in the benefit of the United States.” His framing: “Just because Mythos is not available, open models are available anyhow.”
It is worth noting that Nvidia is one of the partners with access to Mythos already, through Anthropic’s Project Glasswing program. Glasswing has grown from around 50 partners to roughly 200 across about 15 countries, and Anthropic has said models this capable will likely be widely available within 6 to 12 months regardless of what it decides.
– Treasury Secretary Scott Bessent (@SecScottBessent) July 22, 2026
Huang’s comments landed hours after Treasury Secretary Scott Bessent told Fox Business the administration is looking into whether Chinese AI models were built on stolen US intellectual property.
“If we see … that overseas models are stealing from our great companies, we have the ability to sanction them because of this theft,” Bessent said, pointing to what he called “watermarks” of US models showing up inside Chinese ones, with action possible within days or weeks. He also floated whether US companies should have to disclose to customers when they’re running Chinese models.
– Director Michael Kratsios (@mkratsios47) July 22, 2026
Behind the scenes, Axios says this fight has been simmering for a while. US Commerce has been considering blacklisting Chinese AI labs since last year, and the White House had a draft executive order that would’ve made US companies liable for running Chinese models. All of it stalled, but Kimi’s release seems to have brought it back to life.
Jensen Huang split the difference on the “they stole our work” question: “Distillation, learning from AI, learning from other sources of knowledge, is fundamental to intelligence.”
Granted, all this commentary is not coming from a neutral party. Nvidia’s China revenue is basically zero right now, down from a business Huang once said could be worth $50 billion a year. Huang has spent two years arguing against export controls, so of course he’s going to say demand for AI is elastic and that restrictions can backfire. That said, he has also endorsed keeping Blackwell and Rubin out of China’s hands.
The good news is that his core claim could soon be verified. Every number on Kimi K3 so far comes from Moonshot itself or from early API testing. The full weights go public on July 27, and at that point the benchmarks either hold up under independent testing or they don’t.
Anthropic has accused Moonshot of training on 3.4 million Claude conversations earlier this year, though analyst Nathan Lambert’s take is that even if some of that happened, it’s not enough to explain how good K3 actually is. Separately, Epoch AI estimates the gap between the best open and closed models is now down to around three months.
If that gap keeps shrinking, the real question stops being whether US companies should be allowed to use Chinese models, and starts being whether banning them would even do anything once the weights are already sitting on servers everywhere.
Apple is already working on a refreshed version of the MacBook Neo, only a few months after launching its cheapest laptop.
According to Bloomberg’s Mark Gurman, Apple has been testing an updated MacBook Neo with an A19 Pro chip and more memory. The report backs earlier claims that a second-generation model could arrive in 2027, bringing better multitasking performance and improved long-term usability.
The current MacBook Neo runs on a binned A18 Pro chip paired with 8GB of unified memory. It handles browsing, streaming, and everyday productivity reasonably well, but the limited memory can become noticeable once several apps and dozens of browser tabs are running together.

Bloomberg does not reveal the exact memory capacity of the new model. Previous reporting pointed to 12GB, which would give the Neo more breathing room for multitasking and future macOS features. Not to mention that 12GB memory is also a requirement to run advanced Apple Intelligence features locally.
The A19 Pro, which is onboard the iPhone 17 Pro and Pro Max models. should also bring improvements across CPU, graphics, and Neural Engine performance. Apple is reportedly planning to refresh the laptop periodically with new colors as well.
The bigger question is how much Apple will charge. The MacBook Neo launched at $599 in March, but its starting price climbed to $699 in June after rising memory costs forced Apple to increase prices across the Mac lineup. Adding more unified memory could make it difficult to hold the current price, although the Neo would still sit comfortably below the MacBook Air.

There is no word yet on whether Apple will address some of the other compromises found on the first model, including the non-backlit keyboard, mechanical trackpad, and inconsistent USB speeds. The refresh is expected to arrive at the 2027 spring launch event, along with the standard iPhone 18 and the iPhone 18e.
Liam Neeson has a new movie coming out called “The Mongoose” where he does all sorts of Liam Neeson things, including being a man with a “particular set of skills” and getting into a bunch of car chases that likely defy the laws of physics.
Who doesn’t love a good car chase, especially if the cars involved are fun? And therein lies the all-important question of what cars we’re even talking about here. For starters, Liam Neeson’s character drives a Chevy Square Body in a brief part of the trailer. The Square Body is an iconic Chevy pickup that was produced for well over a decade and is still sought after today, but it only has a scant part in all the action.
The bulk of Liam Neeson’s driving takes place in a couple of Ford Mustangs — Shelby Mustangs to be exact. The star Shelby appears to be a red Shelby Super Snake, as indicated by its incredibly aggressive hood vents, widebody package, and giant rear wing. The second blacked-out car also looks to be a Shelby Super Snake, albeit with a more subdued aero package.
Liam Neeson will undoubtedly void warranties and perform stunts in the pair of Shelbys that will likely injure you, damage the car, or both (he’s also running from law enforcement, which is usually a bad idea). But the main draw of the Shelby Super Snake in the real world is the fact that it has 830 hp from the Shelby assembly line and is available with a six-speed short-throw manual transmission.
All that power comes from a supercharged Ford 5.0 Coyote V8 that’s been worked over by Shelby to be much beefier (and louder) than the Ford Mustang GT the Super Snake is based on. The Super Snake Package, which comes with the aforementioned improved V8, giant wing, 20-inch wheels, bodykit, and reworked interior, starts at $108,995. And that doesn’t even include the price of the Mustang GT it needs as a skeleton. All told, Liam Neeson’s car in “The Mongoose” will set back a normal person a cool $176,835.
Ever since the Chevrolet Impala first rolled off the assembly line in 1958, it has been a massively popular car. Not only was the Impala supremely cool in its design, but it was also immediately embraced by pop culture. Films like American Graffiti and Up in Smoke featured Impalas, and the Beach Boys even wrote a song about the car.
Within its first three years on the market, the Impala sold around 68,000 units. After only five years, the count increased to over 800,000. Given that the Impala was sold for over 60 years — from 1958 to 2020 — it’s not surprising that the ending tally wound up in the millions. It turns out that Chevrolet sold nearly 17 million Impalas before the car was discontinued in 2020.
The generational Impala had quite a run, including various design improvements and options. From the Impala Super Sport in 1961 to coupe, sedan, convertible, and wagon models in the 1970s, there was an Impala for just about every taste. However, despite the Impala’s massive popularity over multiple decades, there are cars that have outsold the iconic Chevy. Using a variety of data from manufacturers themselves, along with other sources, we’ve compiled a list of cars that outsold the Chevrolet Impala. Stick around after the list for more on our methodology.
Its styling may not be as iconic as the Chevrolet Impala, but the sheer number of Honda Accords on the road these days has to count for something. As it turns out, Honda claims that the Accord is “America’s best-selling car over the past 50 years.” The first Accord was manufactured much later than the first Impala, but the Accord has definitely racked up more sales.
Honda rolled out its first Accord in 1982, and the car has performed exceedingly well in sales over the years. Although improvements and changes have occurred over 11 iterations of the car (in 11 different generations), there’s still a lot to love — at least, if the sales figures are any indication. In 2026, Honda celebrated its 15 millionth Accord sale in the United States.
However, beyond its 15 million domestic sales, Honda has also sold around 3.7 million Accords internationally, according to data collected and organized by Good Car Bad Car. With a total of 18.7 million sales, the Accord easily beats the Impala’s record. Plus, since the Accord is still manufactured today, that number will only increase over time. Honda Accords are generally considered reliable, and they can last a long time, even as the model is updated. Accord buyers also have options; the 2026 model year is available in various trims, including multiple hybrid trims.
As a former Toyota Camry driver, I had a feeling that the Camry would outperform the Impala, and it turns out the data supports that theory. In my experience, Camrys are comfortable, reliable, and economical, and it seems that might be its primary selling points. In any case, millions of drivers have bought a Camry, outpacing the number of Impala owners by many millions.
In 2017, Toyota marked a milestone with over 18 million global Camry sales; 10 million were within the U.S. At that time, the car was manufactured in 10 different facilities around the world. At the time, Toyota claimed that the Camry was the “best-selling car in America” and had been for 15 years in a row. Since then, Toyota has added around 300,000 Camry sales per year to that figure. By our estimate, based on 2025, 2023, 2021, and 2020 year-end reports from Toyota, drivers have bought an estimated 20.4 million or more Camrys.
Like other modern vehicle models, the Toyota Camry has been in production for a long time and continues to be available. The first-generation Camry rolled out in 1983, and it’s still manufactured today. In 2026, the Camry was only available as a hybrid, with various customizable trims available.
Like the Chevrolet Impala, the original Volkswagen Beetle was discontinued after multiple decades. However, unlike the Impala, the Beetle had a revival — multiple, in fact. The original Beetle body got another chance on the assembly line in the Beetle 1600i from 1970 to 2003. That version, nicknamed the Mexican Beetle for its assembly location, overlapped with various iterations of the New Beetle, which ranged from 1997 to 2010. The third and last generation of Beetle lasted from 2011 until the Beetle was eventually retired.
Though VW nearly replaced the Beetle design, newer iterations of the Bug kept similar styling elements. For example, the Beetle 1600i’s design later inspired the New Beetle’s final trim option, and the third generation echoed the design of the original Beetle. All told, Volkswagen manufactured various Beetles for 70 years, ending with the 2019 Final Edition.
Kelley Blue Book estimated the total Beetle sales to be about 21.5 million, which put the Beetle on our radar as a contender against the Impala. However, a Volkswagen newsroom release confirms that globally, more than 23 million VW Beetles were manufactured and sold. These days, it may be hard to find an older version, especially in decent condition. For that reason, split-window VWs can be worth a lot of money, as can other rarer models.
Like many fan favorite vehicles, the Fiesta was discontinued, with production ending as of 2019. Thus, the Fiesta could have been considered a flop — except that its sales figures were pretty impressive. Having numerous options available, including sedans and hatchbacks with either three or five doors, may have helped the Fiesta’s case.
Plus, the Fiesta first rolled out in the 1970s and lasted until 2019. Especially when compared to the fan-favorite Chevy Impala, the Ford Fiesta’s sales record is nothing to scoff at. A figure quoted from Kelley Blue Book first piqued our interest in the Ford Fiesta. KBB estimated the vehicle has sold more than 22 million units. We found that figure confirmed by a BBC report that documented the production of the final Ford Fiesta in the UK in 2023.
Although the Ford Fiesta was also very popular in the U.S., it was the best-selling vehicle in the UK for over a decade. In 2022, 1.5 million Fiestas were registered in the UK. The very last Fiesta rolled off an assembly line in Cologne, Germany, and it marked the end of an era. After the Fiesta was finished, the facility turned to producing electric models. According to the BBC, the final two Fiesta models were kept by Ford for its collection.
Another vehicle that is as ubiquitous as the Honda Accord or Toyota Camry is the Honda Civic. Therefore, it’s not surprising that the Civic surpasses several vehicles in sales. As Kelley Blue Book noted, over 27 million have been produced to date. Yet the Civic does not seem to be slowing down, so it will continue to surpass the Chevrolet Impala in its sales records. As of 2025, over 27 million Civics have been sold around the world, with a few hundred thousand going to North America each year.
The Civic is a long-lasting part of the U.S. driving landscape in more ways than pure sales figures, too. Honda pointed out that the 11th-generation Civic earned the North American Car of the Year award twice. With each generation of Civic having its own concept, the 11th generation was deemed “exhilarating” by Honda. While non-hybrid Civics are still available, Honda noted in 2025 that it expected hybrid-specific sales to increase.
For 2026, the Honda Civic was still available in standard and hybrid trims, but you may not need a brand-new model if you’re in the market for a Civic. There are plenty of great Honda Civic models to buy used, as long as you do your homework.
As beloved as the Volkswagen Beetle was, that model was apparently not the only one from Volkswagen to smash the Chevrolet Impala’s record. Based on Kelley Blue Book’s data, Volkswagen has sold more than 34 million Passat units. Though the Passat is no doubt a popular model, we weren’t able to confirm the figure, which was also quoted by WhichCar.
CarExpert, a site which compiles data on vehicle sales, estimates over 47,000 Passats have sold throughout the vehicle’s global run. However, totaling the sales data from GoodCarBadCar results in an estimate of about 9.9 million sales. Even Wikipedia doesn’t seem to agree with any of those estimates, so take these numbers with a grain of salt.
Data directly from Volkswagen is also hard to come by. For example, VW noted that U.S. sales of Passat, Dasher, and Quantum models totaled 1.76 million from 1974 to 2020, but no global figure was available. Notably, the Passat is one of VW’s discontinued models, so whatever its total sales, they won’t increase any further, just like the Impala.
Unlike the Volkswagen Passat, the Volkswagen Golf has a well-documented sales history that VW appears to be quite proud of. We first noticed the Golf thanks to Kelley Blue Book’s estimate of over 37 million vehicles sold, and it turns out that the Golf does entirely eclipse the Chevy Impala’s record. Volkswagen confirmed in 2023 that the Golf hit over 37 million sales between 1976 and 2023.
While global sales data for 2024 and 2025 is hard to come by, we can only assume that the Golf continues to grow its sales record. Of course, if we’re looking back all the way to 1974, when it first came out, the original Golf was actually called a Rabbit in the U.S.
Today, the Golf is still available, with the 2026 Golf GTI Hatchback receiving MotorTrend’s Car of the Year award. If you’re in the market for an earlier year (or generation) of Golf, not all Volkswagens have great resale value. However, you can still find many on the road, and the fact that VW continues to manufacture them is a good sign the model will stick around in the future.
Amid the list of quintessential cars beloved by many generations, the Toyota Corolla is a standout. Before seeing Kelley Blue Book’s estimate of more than 42 million units in sales, it was clear the Corolla was a serious contender. Compared to the Corolla’s sales record, the Chevy Impala amounted to peanuts.
Although the Impala had a run of 60 years, the Corolla is at 50-something and counting, with more sales adding on each year. In fact, Toyota confirmed in 2021 that the Corolla had hit 50 million sales globally. Since then, Toyota has sold nearly one million more Corollas in the U.S. alone, according to sales reports spanning 2025 to 2022.
The 12th-generation Corolla has changed a lot since its first rollout in 1966. In fact, the original Corolla cost only about $1,700 (when gas was only 35 cents per gallon). While times have surely changed, the Corolla is Toyota’s cheapest model in 2026, starting at around $23,125. That’s cheaper than other bestsellers on this list, including the Honda Civic (starting at $24,695) and pricier options like the VW Golf (at $34,590).
We began by estimating total Impala sales, then identifying cars that outsold the Impala. Our search led us to a piece by Kelley Blue Book, which was the basis for our list. Where possible, we confirmed or adjusted the sales estimates with external sources. Then we explored other popular vehicle models, confirmed their total sales, and ranked them accordingly.
Though we did our best to compile the most recent data possible, not every manufacturer publicly posts data in a consumer-friendly format. Thus, our estimates may be rough, as well as slightly behind current counts due to the timing of yearly sales releases (for example, 2026 data may not be available until well into 2027).
paas and iaas
It’s Alphabet’s fastest-growing business and now makes up more than a fifth of the juggernaut’s revenue and operating profit
Since the beginning of the year, several people have remarked to me off the cuff, apropos of nothing in particular: “Google Cloud is killing it.”
Parent company Alphabet reported Q2 earnings [PDF] after the bell on Wednesday and the numbers speak for themselves. Let’s go to the tape:
Google Cloud revenue was up 82 percent from the same quarter last year, increasing from $13.6 billion to $24.8 billion.
Google Cloud operating income more than tripled during the same period, going from $2.8 billion to $8.8 billion.
Once the distant-third-place laughingstock of the IaaS platforms, Google’s cloud business is now the growth engine of Alphabet and a significant contributor to the company’s overall business, making up 21 percent of revenues and 22 percent of operating income.
How’d this magic happen? The company’s claiming it’s all AI, citing “demand for AI infrastructure and AI solutions.”
We have no idea if that’s actually the case, given the plethora of more prosaic offerings from the Google Cloud team, but the company’s Gemini marketing strategy – pushing it in front of hundreds of millions of searchers every day – can’t be faulted.
Informal checks against our own sources suggest Anthropic Claude remains the go-to frontier model for most enterprise customers, and we’re definitely hearing about companies switching between models to make the most of token costs vs effectiveness. But when the AI bubble finally pops, it could bring down money-losers OpenAI and Anthropic, and maybe even Oracle, which has gotten in a bit too deep.
Google, like the janitor at the end of the universe, will be there to pick up the pieces – and talent. ®
Have you ever been looking up a recipe for something new and been stymied by the directions being a wall of text, especially to find that one detail right when you’re in the middle of making the dish? Recipe Lanes by [bohemian-miser] leverages an LLM to create flow charts to make the process more straightforward.
As someone who has mostly avoided LLM use thus far, I found the examples in the Gallery helped inform what the LLM was expecting for prompts as my first attempts were unsuccessful. Once you know the language expected from the computer, you can get it to generate icons for each ingredient and a flow chart of the steps to cook the food. While it does organize the chart when it is generated, each element can be independently moved across the canvas to put things in a more sensible order, especially as I found it can generate elements with overlapping text.
The 8-bit icon style and button text on the site give it a fun bit of flair that adds to the overall experience. The tool is still in its infancy, but it’s Open Source, so we hope to see it improve over time. If you’d like to see some more interesting kitchen hacks, how about ramen in edible packaging, this rotary phone kitchen timer, or these automated Arduino splash guards.
When Hugging Face got hit last week, co-founder Clement Delangue suspected a frontier lab, given the agent’s sophistication. He was right. Delangue said on X that after a day working with OpenAI he strongly believed there was no malicious intent and that it was mind-blowing the whole thing had happened autonomously.
The two OpenAI models that broke into Hugging Face last week did not breach it through malice or superintelligence. They breached it through credentials and permissions they should never have been able to reach, a non-human identity failure that is the oldest problem in security rather than the newest one in AI, and the one every enterprise can actually fix.
OpenAI disclosed on July 21 that two of its models, GPT-5.6 Sol and an unreleased, more capable model, were running a cyber benchmark called ExploitGym with their safety refusals switched off, and inferred that the answer key sat in Hugging Face’s production database. Getting there took two different failures. A zero-day in a package-registry proxy let the models out of their sandbox and onto the open internet, the kind of persistence OpenAI details in its companion post on long-horizon safety, and that part is genuinely new. The breach of Hugging Face itself came the ordinary way. OpenAI’s own account is that the models chained stolen credentials and further zero-days into a remote code execution path, after a series of privilege escalation and lateral movement steps. The exotic part got them to the door, and credentials walked them through it.
Hugging Face also disclosed last week that an autonomous agent had harvested cloud and cluster credentials scoped broadly enough to reach multiple internal clusters, then left a trail of more than 17,000 recorded events across short-lived sandboxes over a weekend. Both disclosures describe the same escalation. An agent lands somewhere it should not be, finds credentials scoped far wider than any task requires, and uses them to move. These are two accounts of one incident, not two attacks. The agent Hugging Face watched was OpenAI’s models, and both companies describe the same ordinary escalation.
The version of this in a typical enterprise is worse, not better. OpenAI and Hugging Face are among the most security-mature organizations in the industry, and both still needed the intrusion to happen before they could see it. The average company wiring agents into Copilot or an internal assistant has neither the identity inventory nor the behavioral monitoring those two brought to bear. The same breach in a normal company would not be contained in days, it would simply go unnoticed.
The reaction has split into familiar camps. Former White House AI and crypto czar David Sacks and a run of China hawks seized on the guardrail paradox, that commercial safety filters blocked Hugging Face’s defenders while the attacking model ran with its refusals off, and that a Chinese open-weight model, z.ai’s GLM 5.2, was what finally let the team finish its forensics. Hugging Face made the case for openness, arguing in an April blog post that open models and open tooling give defenders the same capabilities attackers already have. Both arguments are about the model, and neither touches the mechanism.
Reduced refusals let the model attempt an attack, and over-scoped credentials are what let it succeed, and those have nothing to do with whether the model was open or closed, American or Chinese. Making a frontier model provably safe is a multi-year alignment problem no customer can buy or accelerate, while scoping an identity is a configuration change a team can ship this sprint. The industry is being urged to fixate on the part of this it cannot control and to treat the part it can as a footnote.
Forrester reached the same read. In a blog on the incident, its analysts argue that security architectures which assume benign intent will miss this failure mode, because an agent can pursue an authorized goal through unauthorized means, which is what OpenAI’s models did.
Strip the science-fiction framing and what remains is a textbook case of over-privileged machine identity, the kind security teams have fought for a decade, now driven by an autonomous agent at machine speed. Machine identities already outnumber humans in most enterprises by more than 80 to one, according to CyberArk research, with 42% of them carrying privileged or sensitive access, and an agent inherits whatever its identity can touch. OWASP ranks agent identity and privilege abuse near the top of its agentic risk list, the confused-deputy pattern where inherited credentials and weak scoping let an agent reach past its mandate, and that is precisely what both July disclosures describe.
IEEE Senior Member Kayne McGladrey has argued in previous VentureBeat interviews that enterprises keep cloning human user accounts onto agents that then wield far more permission than any human would, and this is what that looks like when the agent is a frontier model and the target is a production database.
The people closest to it read it the same way. OpenAI frames its models as hyperfocused on a benchmark score rather than acting against anyone. Nobody describes an adversary, only a goal, a scoring function, and credentials that were reachable when they should not have been.
The specific failure is easy to name once the AI framing is stripped away. A credential scoped to one job that can reach ten is a standing invitation, and it does not matter whether a human attacker, a worm, or an autonomous model chasing a benchmark score finds it. What changed in July is the finder. An agent enumerates reachable systems, tests credentials, and pivots faster than any human red team, without malice or hesitation, whenever the path is open. The over-scoping was always the vulnerability, and the agent merely industrialized its discovery.
Forrester named the control that would have blunted it. Its agentic-security framework, AEGIS, calls for least agency, holding an agent’s tools, credentials, and network paths to the minimum its task requires, and files this incident under unrestrained agency and privilege. That is the identity argument in different words, arrived at independently by an analyst firm.
The data says this is where the risk now lives. Verizon’s 2026 Data Breach Investigations Report found that exploitation of vulnerabilities has overtaken stolen credentials as the top initial access vector for the first time in 19 years. That is the initial-access half. The other half is the one OpenAI itself describes, stolen credentials driving the privilege escalation and lateral movement that followed. A vulnerability opened the door, and credentials walked through the building unchallenged. Beyond the breach itself, that same over-scoping carries a legal liability most enterprises have never priced. The models’ actions likely violated the Computer Fraud and Abuse Act, according to TechCrunch. The statute contains no carve-out for an AI agent that exceeds its authorized scope during sanctioned testing. Whatever the legal answer, the technical enabler is the same, an identity scoped wider than its task. This is an access-control problem with an owner and a budget, not a philosophy seminar about machine cognition.
Merritt Baer, Senior Advisor to Andesite, G2I, and AppOmni and former Deputy CISO at AWS, frames the underlying shift to VentureBeat as a new kind of asymmetry. Both sides now reach for the same capabilities, she said, but one side is constrained by enterprise governance, policy, compliance, and safety controls while the adversary simply downloads an uncensored open-weight model and keeps going. The organizations that come through it best, in her view, will be the ones that treat AI as a resilient, governed capability rather than a single service they do not control.
The breach worked because the agent reached identities scoped far wider than its task. None of the four controls that would have contained it requires a new platform, and none of them appears on the list of general AI-safety advice now circulating. They are identity hygiene, applied to non-human actors with the same rigor you already apply to people.
1. Scope every non-human identity to one task. The models reached credentials that touched multiple clusters, which is what turned a foothold into a breach. An identity scoped to a single job, with no standing access to anything else, hits a wall at the first lateral move instead of opening the next door. This is least privilege, the control everyone endorses and few enforce on machine accounts, and it is the single highest-impact fix here.
2. Give credentials short lifetimes and rotate them hard. Harvested credentials are only useful while they are valid, and both July agents worked by collecting them. Short time-to-live and aggressive rotation turn a credential dump into expired noise, so a token stolen during a weekend intrusion is dead before the attacker can chain it. Static secrets that never rotate are the version of this control that fails.
3. Monitor for lateral movement, not just prompts. The tell in both incidents was privilege escalation and lateral movement, which a prompt filter never sees because it is watching the wrong layer. Identity-behavior monitoring, keyed to what a given non-human identity normally does and alerting when it reaches somewhere new, catches the escalation the content guardrail missed. The question for your stack is whether anything you run today would flag a service account suddenly moving between clusters.
4. Rehearse instant revocation before you need it. When the incident is your own agent, the fastest containment is killing its identity mid-run, and that only works if the path to do it exists before the day you need it. Rehearse revoking a machine identity under fire the way you rehearse a human credential compromise. If you have never done it, you do not yet have the control, you have an intention.
The defense also worked, and that matters. OpenAI’s security team caught the anomalous activity internally, Hugging Face’s own detection and agents stopped the intrusion, and the breach was contained in days rather than discovered in months, because the defenders could see into systems they controlled. That visibility is the same discipline the four controls depend on. The debate over whether frontier models are safe, open, or American will run for years, and none of it will be settled in time to help the enterprise deploying agents this quarter. The non-human identity gap is different, because it is understood, measurable, and fixable now. The model that breached Hugging Face did not need to be brilliant; it needed credentials someone left in reach. The fix is scoping them before an agent finds them.
Ctrl-Alt-Speech is a weekly podcast about the latest news in online speech, from Mike Masnick and Everything in Moderation‘s Ben Whitelaw.
Subscribe now on Apple Podcasts, Overcast, Spotify, Pocket Casts, YouTube, or your podcast app of choice — or go straight to the RSS feed. To get extended episodes with additional coverage, support us on Patreon.
In this sponsored Spotlight episode of Ctrl-Alt-Speech, host Ben Whitelaw speaks to PwC’s Dan Hays at TrustCon about the firm’s recently published Trust & Safety Outlook report.
They discuss:
The conversation also explores how Trust & Safety is becoming a more strategic function inside companies, how automation could change the role of practitioners and vendors, and which emerging risks remain most underestimated.
This episode is brought to you in conjunction with our sponsor, PwC. Download the report today.
Filed Under: ai, artificial intelligence, content moderation, trust and safety
Companies: pwc
Alphabet investors have very publicly worried that the company’s massive AI spending isn’t worth the money. With the company’s latest earnings report, those investors should be able to relax a little.
The takeaway: Google’s cloud business — driven largely by enterprise AI adoption — is booming. The search giant saw Google Cloud revenue spike 82% from where it was this time last year, climbing to $24.8 billion. That’s well above last quarter’s generous year-over-year growth, which showed a revenue jump of 63% to $20 billion — and it handily beats what Wall Street analysts expected for this quarter’s growth (the expectation was $22.46 billion).
Those cloud gains were driven largely by enterprise AI solutions and enterprise AI infrastructure adoption, the company said, while also noting that its backlog of cloud contracting work — that is, work that it hasn’t yet converted into revenue — had climbed to $514 billion.
The company’s profit hit $112.1 billion, which is a massive jump from this time last year, when the company reported $28.1 billion in profit, the company’s earnings report shows. Meanwhile, Alphabet’s overall revenue grew 24% year-over-year during the past quarter to $119.8 billion. The company also saw Google Services revenue jump 15% to $94.5 billion.
“Our AI investments are redefining what’s possible across every part of our business,” said Google CEO Sundar Pichai during Wednesday’s earnings call. “We have exciting momentum across the board.”
More people are also adopting Gemini, Google’s AI chatbot, as the app currently enjoys 950 million monthly active users, the company said. In Q4 of 2025, Google reported that the app had 750 million users.
It’s worth noting that spiking revenue isn’t unusual for Google. This marks the company’s 12th consecutive quarter of double-digit revenue growth. But even by that standard, this quarter represents a particularly bountiful period for the tech giant.
Alphabet’s spending is still hefty, with its capital expenditures — the money it spends building data centers, buying chips, and expanding infrastructure — estimated to be between $180 billion and $190 billion for the year — a fact not lost on analysts during Wednesday’s earnings call. Several pressed Pichai on when, and how much, those investments will pay off.
“I think our compute capacity investments in ’27,” he said. “We are seeing strong demand indicators, including long-term deals,” he continued. “I think, if anything, the dynamics look healthier than where we were about a year ago, so that’s what gives us the confidence to undertake those investments,” he said.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
The Steam Machine is already one of Valve’s most expensive gaming devices. However, it may not stay at its current price for long.
According to a Valve engineer, the ongoing DRAM shortage is continuing to drive up component costs. This raises the possibility that the handheld could become even more expensive in the months ahead.
Speaking to Bloomberg’s Jason Schreier, Valve engineer Yazan Aldehayyat said the company expected some supply chain challenges around memory, storage and chips. However, he said the current DRAM crisis has turned out to be far more severe than anticipated.
While he stopped short of confirming another price increase, Aldehayyat suggested that the worst may not be over. He explained that retail prices typically lag three to six months behind wholesale component costs. This means the most recent increases in DRAM pricing have yet to be reflected on store shelves.
That could have implications for the Steam Machine, which already starts at £879 / $1,049 for the version with 512GB of storage and no controller. Buyers looking for the 2TB model with a bundled gamepad currently have to pay £1,208 / $1,428.
The comments also suggest Valve is continuing to monitor the supply situation closely rather than ruling out future pricing changes. Aldehayyat noted that it’s still unclear whether memory prices will eventually stabilise or continue climbing. As a result, it is difficult to predict where hardware costs will settle over the longer term.
The Steam Machine has already weathered one major price adjustment. According to the report, Valve had originally intended to launch the device at a lower price. However, rising component costs forced the company to increase pricing ahead of release. The increase was compared to previous price changes affecting the Steam Deck.
Despite its premium positioning, demand doesn’t appear to have slowed. The Steam Machine is reportedly sold out, suggesting buyers have continued to snap up the hardware even at its current asking price.
For now, Valve hasn’t announced any official pricing changes, and Aldehayyat’s comments don’t confirm that one is imminent. However, if memory costs continue to rise and supply pressures persist, today’s retail prices may not be the final word on what the Steam Machine will ultimately cost.
London Mayor Sadiq Khan handed a peerage by Keir Starmer alongside 15 other Labour figures… just days before the PM leaves No10
Weekend Open Thread – Corporette.com
The House | The City of London can help the new chancellor deliver growth in every postcode
Two July Windows Left: The CLARITY Act’s Senate Fight and What Failure Means
Ripple Payments Joins MiCA With 14 Firms, Does It Mean Anything For XRP?
Nvidia Stock Slips After Big Tuesday Rally as Huang Confirms Vera Rubin Chip Is Now in Production Today
Democrats look to World Cup watch parties to register thousands of voters
Ripple wins EU-wide access as ESMA adds it to MiCA register
Grayscale Files For Worldcoin ETF, WLD Registers Sharp Rise
Unregistered fitter used Gas Safe logo on business flyers
Sail Virtually Aboard The “Itanic” With IA-64 Emulator
Injective Submits SEC Transfer-Agent Registration to Onchain Ownership Records
Palantir Shares Rise After Expanded Nvidia Partnership and Fresh Analyst Upgrades Ahead of Earnings Day
Turtle Beach Command Series KB7 review: a nifty screen-equipped gaming keyboard
Registration is now open for March for Men with Kev 2026
New Jersey voter registration controversy explained: How 6,600 noncitizens got on the rolls, and what happens next
Claude Fable 5 Slips to Second in AI Coding Leaderboard
Money | Class 12 Economics | CBSE Board Exam 2026-27
Banco Bilbao Vizcaya Argentaria, S.A. (BBVA) Discusses Global Macro Environment and Economic Outlook for Core Markets Transcript
Kaspersky exposes OkoBot’s 20-module crypto wallet attack
You must be logged in to post a comment Login