- Brex Startup Community Weekly Newsletter
- Posts
- most epic week in AI ever!
most epic week in AI ever!

Happy Tuesday Brex Community,
I just got back from a vacation and choose a hec of time to be on the beach in Maui, mainly unplugged & was able to reset 🙏 The TLDR is that these past 7 days are the most consequential when it comes to AI, really big news and below is recap of what happened, it’s a lot but worth a read if in case you missed any of it.
OpenAI's agent went rogue and hacked Hugging Face
Hugging Face disclosed that it had been hit by what it called an unprecedented AI-led attack, something completely different from anything the company had dealt with before. The intrusion involved an autonomous agent running thousands of individual actions across a swarm of short-lived sandboxes, with command and control infrastructure that kept migrating across public services.
After investigating, OpenAI admitted the agent was its own. It was powered by a combination of models, including the recently released GPT-5.6 Sol and an even more capable unreleased model, both running with reduced safety refusals because they were being tested internally on a cybersecurity benchmark. The agent found a real zero-day vulnerability, used it to escape its supposedly isolated test environment, reached the open internet, and then made its own call to target Hugging Face specifically because it judged that Hugging Face might hold the "answer key" to the benchmark it was being evaluated on.
Nobody told it to do that. That's the part that has security researchers rattled. One cybersecurity fellow described the setup as basically locking a student in a room and telling them to be as bad as possible, then coming back to find they'd broken out and gone looking for the teacher's answer key. Experts are split on whether "rogue" is even the right word since the agent was doing exactly what it was incentivized to do, just far more effectively and independently than anyone expected.
The cleanup got its own subplot. Hugging Face's security team initially tried using frontier models to analyze the attack, but the guardrails on those models couldn't tell the difference between defending the system and attacking it, so the process was too slow. The team ended up leaning on an open-weight Chinese model instead, which kept all the forensic work in-house with no data or credentials leaving their environment. That detail is landing awkwardly in Washington, where lawmakers are simultaneously trying to restrict the use of Chinese AI models over security concerns.
OpenAI says it's tightening infrastructure controls, briefing its Safety and Security Committee regularly, and working with Hugging Face on a full forensic investigation.
Official accounts: Hugging Face's incident disclosure and OpenAI's post on the security incident.
Nvidia rallies the industry behind open weights, and OpenAI eventually joins
On July 24, a coalition organized around Nvidia published a letter called "Open Weights and American AI Leadership," arguing that the US keeps its AI edge by supporting open, downloadable models rather than restricting them. Nvidia CEO Jensen Huang used it to publish his first-ever post on X, which pulled in tens of millions of views within days.
The original 25 signatories were a mix of chipmakers, cloud providers, enterprise software companies, and model builders: Microsoft, Meta, IBM, Dell, Palantir, Hugging Face, Mistral, Perplexity, Andreessen Horowitz, the Linux Foundation, and Y Combinator among them. The letter pushes back on the idea of broad restrictions on Chinese open-weight models, arguing that concerns about technology theft should be handled through targeted legal and commercial tools rather than blanket bans, and that open weights and distillation are separate issues that shouldn't be conflated.
What got almost as much attention as the letter itself was who didn't sign it. OpenAI, Anthropic, and Google, the three companies most invested in closed frontier models, were conspicuously absent at launch. That didn't last. Within days the list roughly doubled to 50 names, adding OpenAI, Google, AMD, Cisco, Cloudflare, GitHub, and others. Amazon signed last night. xAI hasn’t signed but SpaceX has and Elon has endorsed the letter. Anthropic is the last big hold out but they post their POV last night on the matter, see further on in the post.
The timing isn't a coincidence. The letter landed one day after a bipartisan bill was introduced in Congress and amid reports that the White House is weighing new restrictions on Chinese open-weight models. Separately, the administration has accused China of large-scale theft of AI technology from US companies including Anthropic. Whatever you make of the letter's civic-minded framing, it's fundamentally a lobbying document aimed at shaping policy that hasn't been written yet.
You can read the official letter, hosted by Nvidia, here: Open Weights and American AI Leadership (PDF).
Quick explainer: what "distillation" actually means, and why everyone's arguing about it
If you've seen the word "distillation" everywhere this week and weren't totally sure what it meant, you're not alone, it was probably the single most argued-about concept in this whole news cycle. Worth clarifying up front: distillation isn't reverse-engineering a model's actual weights (the billions of numbers that make up the trained network). Nobody's popping the hood and copying out the parameters directly, those stay locked inside the company that trained them. What actually happens is more like an apprenticeship. A smaller "student" model is trained by feeding it huge volumes of questions and then learning to imitate the outputs of a bigger "teacher" model. Do that at large enough scale, sending millions of queries and studying the answers closely enough, and the student model can end up mimicking a meaningful chunk of the teacher's capabilities without ever touching its actual weights. In effect, you're reconstructing the teacher's behavior from its outputs rather than lifting its internals directly, which is close to what people mean when they call it reverse-engineering, even though it's technically a different mechanism than that phrase implies.
This is exactly why it became such a live issue this week. Anthropic told the US Senate Banking Committee that Alibaba's Qwen lab ran what it's calling the largest known distillation campaign ever conducted against Claude, allegedly using around 25,000 fake accounts to send Claude something like 29 million queries specifically structured to extract training signal for its own models. US Treasury Secretary Scott Bessent waded in publicly too, saying the administration supports open-source AI but drew a hard line: open source isn't "open season on American IP," and covert, industrial-scale distillation campaigns crossing into IP theft could bring sanctions and Entity List designations for the companies behind them.
The Nvidia-organized letter tried to get ahead of exactly this argument. It explicitly separates the two concepts, arguing that open weights and distillation are not the same thing and that lawmakers shouldn't conflate legitimate model development techniques with outright misappropriation. Its logic: a model can be open-weight without ever having been trained through distillation, and a closed, proprietary model can just as easily use distillation techniques itself. So regulating one doesn't actually solve the other, and broad restrictions aimed at open weights could miss the actual bad behavior entirely.
That's the crack Amodei's response exploited. He agreed distillation is a real problem worth cracking down on hard, he's just skeptical that a voluntary industry letter is the mechanism to do it, especially when his own company says it's on the receiving end of the largest example anyone's documented. He also admitted the practical difficulty candidly: abusive accounts running a distillation campaign are often only identifiable after a lot of the damage is already done, which is part of why he's pushing for targeted enforcement measures rather than trusting the market to sort it out on its own.
Anthropic finally breaks its silence
Anthropic was one of the notable holdouts from the letter, and its silence over the weekend was getting loud enough that people started reading it as an attempt to protect its own commercial position. Dario Amodei answered that directly last night with a blog post laying out the company's actual position.
His headline point: Anthropic has never advocated for banning open-weight models as a category, and he says so explicitly, adding that open-weight models without dangerous capabilities are a public good. Where he pushes back on the Nvidia letter is narrower than a blanket "open bad, closed good" stance. He agrees open weights expand access and competition, but disputes the letter's implication that openness mostly helps defenders rather than attackers. His sharpest example is biological weapons: a capable enough model could help someone weaponize a dangerous pathogen quickly using materials that are already easy to get, while building real defenses against that kind of threat takes years. Once weights are out, there's no recalling them if a serious risk shows up later.
He also pushed back on the letter's move to separate open weights from distillation entirely, since that's the part of this fight that touches Anthropic's own business most directly given the Qwen allegations covered above. Rather than pushing for bans, he laid out narrower measures he'd rather see: things aimed at specific bad behavior like industrial-scale distillation and IP theft, not restrictions on open-weight releases as a category.
It's a more nuanced position than "Anthropic wants open weights banned," but it keeps the company positioned as the clearest voice of caution in this fight, especially with the Hugging Face breach as a very recent, very real example of exactly the kind of containment failure Amodei is warning about.
Read Dario's full post here: Our position on open-weights models.
Moonshot AI ships the largest open-weight model ever built
While that policy fight was heating up, Chinese lab Moonshot AI quietly settled the "who has the biggest open model" question. Kimi K3, a 2.8 trillion parameter mixture-of-experts model, went live with full open weights on Hugging Face on July 27, a day ahead of its original schedule. That makes it the largest open-weight model publicly released to date, edging past everything else in that category.
Some notable specs: a one million token context window, native multimodal support (text and images), and an architecture that only activates a fraction of its parameters per token, so despite the enormous total size it runs more like a mid-size model on a per-token basis. In blind testing by the evaluator Arena, developers reportedly preferred Kimi over leading closed US models, including offerings from OpenAI and Anthropic, specifically for front-end coding tasks. The full weights come in at roughly 594GB under 4-bit quantization, still large enough that self-hosting realistically means renting serious cloud infrastructure rather than running it on a personal workstation.
Moonshot's founder has said openly that the strategy is to grow market share through openness in a way the closed US labs generally haven't matched. It's a pointed move given everything happening in the open weights policy fight above, and it's already fueling both excitement and anxiety in Washington and Silicon Valley about how much of the performance gap between US and Chinese AI has closed.
Official source: Moonshot AI's Kimi K3 tech blog.
Stripe is reportedly buying OpenRouter, and it's really a story about token routing
The other big thread this week ties directly back to everything above: money is following the shift toward cheaper, often Chinese, open-weight models, and the middlemen who route traffic between different AI models are suddenly extremely valuable.
The headline version: the Wall Street Journal reported that Stripe is in talks to acquire OpenRouter, the marketplace that lets developers send requests across hundreds of AI models from a single interface, in a deal that could value the startup at around $10 billion. That's roughly eight times its $1.3 billion valuation from a funding round just two months earlier, in May. Nothing is signed yet and the talks could still fall apart or draw a competing bidder, but people familiar with the discussions say an announcement could come soon. Stripe and OpenRouter already have a relationship, OpenRouter uses Stripe's invoicing, tax, and fraud tools to bill its own customers, so a full acquisition would formalize something that's already operationally close. It would also be Stripe's second AI infrastructure purchase in under a year, following its acquisition of usage-metering company Metronome in January.
Why does a payments company want to own an AI model router? Because tokens are starting to behave like currency. As more companies split their AI workloads across multiple models instead of defaulting to one frontier provider, whoever sits in the middle collecting a cut on every request looks a lot like a toll booth, which is exactly the kind of business Stripe already understands. OpenRouter's own cofounder has described the company as an AI equivalent of Stripe.
That toll booth is getting busier for a specific reason: cost. Reporting this month put Chinese open-weight models, DeepSeek, Alibaba's Qwen, and now Kimi K3, at somewhere between 58% and 63% of the token volume that US companies are routing through OpenRouter, up from under 10% a year ago. DeepSeek alone is reportedly the single largest vendor on the platform. Companies like Airbnb and food-delivery startup DoorDash have both said they use Chinese models specifically because they're dramatically cheaper, in some cases cutting inference costs by as much as 90% compared to switching away from providers like Anthropic. That price gap is a big part of why Treasury Secretary Bessent's sanctions threat over distillation, mentioned above, is such a live wire: a meaningful chunk of US enterprise AI spend is already flowing through the exact models Washington is discussing restricting.
Stripe isn't the only one circling this space either. Cursor launched its own routing product this same week, chasing the same insight: as AI bills climb, companies want a layer that automatically sends easy tasks to cheap models and hard tasks to expensive ones, rather than paying frontier prices for everything by default. That's a genuine structural risk for OpenAI and Anthropic's business models if it takes hold broadly, since their valuations lean on the assumption that customers keep defaulting to premium usage rather than shopping around token by token.
Hope this recap was helpful, a lot going on and hard to track all of it. Have a great week!

Align Ventures: The Consumer Brand Builders Quietly Crushing It
While most of venture capital chases the next frontier AI model or robotics moonshot, Align Ventures is doing something refreshingly grounded and highly effective. The Miami-based firm just closed its $125 million Early-stage Fund II (surpassing its $100 million target), and the timing couldn’t be better for anyone watching the next wave of everyday consumer innovation.
Align backs brands that transform how people live: beauty, personal care, wellness, health, pet, and home. Think Touchland (hand sanitizer that became a cultural staple, later acquired by Church & Dwight), Coterie (diapers acquired by Mammoth Brands), Billie, Hims, Starface, Olipop, and more recently California Naturals. They write $2–10 million initial checks into 15–20 companies per fund, often as an early institutional partner that sticks around with real operational support.
What makes them interesting isn’t just the exits, though those matter. It’s the combination of cultural taste and disciplined capital. In a market obsessed with software multiples, Align has shown that brand-led consumer businesses can still deliver top-decile returns when you pick the right founders and stay close. Fund I already proved the model; Fund II arrives with returning LPs plus new ones, plus a team that has expanded to keep pace.
They’re not trying to be the biggest firm in Silicon Valley. They’re building a focused platform for the next generation of products people actually use every day, and that focus is paying off. In a world of AI hype cycles, Align’s quiet competence in consumer feels like a smart counter-bet.

Events you might see us at - subscribe here - all focused on Founders, VCs & Finance leaders:
July 30 - SF - AI pitch night at Brex - Apply Here
Aug 5 - NYC - Brex Yacht Club - open to recently VC funded startup founders - Apply Here
Aug 6 - NYC - free ice cream , pull up! - Apply Here
Aug 18 - Chicago - Brex Mode - for finance leaders - Apply Here
Aug 25 - Austin - Brex Mode - for finance leaders - Apply Here

Sign up here for Brex and receive $1,250 towards Brex Travel or $750 cash
Brex is the intelligent finance platform built for speed and control. Combining corporate cards, banking, treasury, expense management, bill pay, travel, and accounting, Brex helps companies spend smarter and move faster in 120 countries. By integrating AI across every workflow, Brex enables founders and finance teams to eliminate manual work, do more with less, and accelerate impact. More than 35,000 companies from startups to enterprises run on Brex, including Anthropic, OpenAI, Cursor, Granola, ServiceTitan, Robinhood, DoorDash, etc.



