Name’s on the list? Sup, VIP. It’s your boy Eric! Last edition I told you Nvidia was circling Hugging Face and nothing was signed yet. Welp, it got signed. Then OpenAI, Anthropic AND Google each released their most capable model and put a bouncer at the door, all within three days. That wasn’t on my bingo card, but here we are!
The short version: Nvidia confirmed the Hugging Face deal at $12.93 billion. OpenAI said its Astra model crossed the top rung of its own safety scale for hacking. Anthropic put out one model at two security levels. Google did roughly the same thing with a program called Fairwind. And OpenAI quietly bought a mountain of Mac minis. Let’s get into it.
Here’s what’s covered today:
Nvidia confirmed it is buying Hugging Face for $12.93 billion, five business days after the reports I covered last edition
OpenAI says Astra is the first of its models to hit “Critical” on its own cybersecurity scale, and the strongest version goes only to people who apply
Anthropic released Claude Fable 5.1 to everyone and Claude Mythos 5.1 to approved users only
Google shipped Gemini 3.8 Flash to the public and made you apply to get the security version
OpenAI bought tens of thousands of Mac minis and Mac Studios to train agents that use a computer the way you do
Nvidia signed the papers on the biggest open-source AI site
The story: As I mentioned last week, Hugging Face is the public library of AI. Devs upload the models they build, other devs download and run them, and it works roughly the way GitHub works for code. Last edition I covered the reports that Nvidia was closing in for about $12.9 billion, with nothing signed and a real chance the talks fell apart. On September 3, Nvidia confirmed the agreement on its own blog.
What happened:
Nvidia announced the deal September 3 at $12.93 billion, in a post on its corporate blog
The Information first reported the roughly $12.9 billion figure on August 26, which is what I covered last edition
Jensen Huang’s line in the announcement: “Together, we will scale Hugging Face’s platform, strengthen its infrastructure and expand access to AI for devs”
Nvidia says the platform stays open, and that devs keep choosing “the models they want, the frameworks they want, the clouds and inference service providers they want and the computing platforms they want,” with no requirement to run on Nvidia hardware
CNBC reported that Hugging Face approached Huang weeks before the agreement, and Nvidia’s post says nothing about closing conditions or a regulatory timeline
Nvidia makes chips (and not the edible kind, unless you’re rich AND have a penchant for eating non-foods). Now Nvidia owns the site where devs go to download models, and a lot of those models run on chips from AMD and Google. Devs use Hugging Face because… well… let’s face it, almost everybody uses Hugging Face. If devs start feeling pushed toward Nvidia hardware, they will move somewhere else. So people are going to watch whether Nvidia keeps that promise about staying open, and Nvidia put the promise in writing on its own blog. Ayyyy, one “What I’m watching” bullet down.
OpenAI says its next model is too good at hacking to hand out freely
The story: On September 1, OpenAI said Astra is the first of its models to reach “Critical” cybersecurity capability under its Preparedness Framework, the internal scale it uses to rate how much damage a model could do. Critical means the model can find security holes nobody knew about and build working attacks on well-defended systems without someone at the helm, steering things.
What happened:
OpenAI published the Astra announcement September 1 and called it the first model to meet the Critical cybersecurity threshold
A zero-day is a flaw nobody has patched because nobody knew it existed, and in testing Astra found two of them and chained them together
Amelia Glaese, OpenAI’s VP of Research: “Astra can find previously unknown security flaws and develop ways to exploit them across many well-protected systems without a person guiding each step”
Astra scored 100% on ExploitBench, refuses 91.5% of disallowed cyber requests against 59% for GPT-5.6 Sol, and made zero unauthorized compromise attempts in honeypot testing against Sol’s 56%
A broad version is coming, while the strongest cyber features go to a small group of alpha testers first and then to defensive security professionals through a program called Daybreak Blue
OpenAI ran the tests and decided this one was too strong to hand out to everybody. After all, no one needs a hammer that can also fire bullets. So, the strongest version of this goes to a small group of testers first, then to security professionals who apply to Daybreak Blue. Everybody else gets regular ol' vanilla Astra when it ships.
Anthropic released the same model twice, with different rules
The story: Also on September 1, Anthropic released Claude Fable 5.1 and Claude Mythos 5.1. Both run on the same underlying model and differ in their safeguards. Fable 5.1 is public. Mythos 5.1 goes only to people accepted into Anthropic’s trusted access programs, with protections built for cybersecurity and life sciences work.
What happened:
Anthropic released both models September 1, describing them as its most advanced for coding and knowledge work
Fable 5.1 and Mythos 5.1 share the same underlying model, and the safeguards are what separate them
Mythos 5.1 is available only through trusted access programs, aimed at vetted users in cybersecurity and the life sciences
Fable 5.1 runs roughly 25% cheaper than Fable 5 on standard work, and up to 45% cheaper on complex agentic tasks
Anthropic says Fable 5.1 matches or beats Fable 5 at low and medium effort settings
Same model, two versions. Anthropic cut the price on the one anybody can use. But the one that’s as good at hacking as portrayed by every hacker in a 90s movie (and, oh yeah, biology work)? That one is behind an application. Big bucks do not get you Mythos 5.1. You have to qualify.
Google put its bug-fixing model behind an application form
The story: On September 2, Google released Gemini 3.8 Flash and Gemini 3.8 Flash Cyber, its third Flash release in six weeks. Flash is public. Flash Cyber finds security flaws and writes the patches to fix them, and Google restricts it to defenders it has vetted through a new program called Fairwind.
What happened:
Google announced both models September 2, the third Flash release in a six-week stretch
Gemini 3.8 Flash is open to devs and consumers at introductory pricing of $0.75 and $3.75 per million tokens
Gemini 3.8 Flash Cyber handles vulnerability detection and automated patching, and access requires approval
Fairwind is the program handling that approval, open to government authorities, critical infrastructure operators and software maintainers
Google reports 47.2% pass@1 on CWE-Bench, above 70% success across 20 programming languages on an internal benchmark, and 2.6x more correct patches than leading commercial alternatives in Chrome Security testing
Three companies, three days, and three application forms (but sadly, not 3 pizzas for $3). Google built its version to fix things, so Google gave it to the people who fix things: government agencies, power and water companies, and the volunteers who maintain free software that almost every app uses. A regular dev clicks a button and has Gemini 3.8 Flash today. To get the Cyber version, that same dev needs to fill out a form and wait for Google to say yes.
OpenAI is buying Mac minis by the tens of thousands
The story: On August 31, The Information reported that OpenAI purchased tens of thousands of Mac minis and Mac Studios. They are training computer-use agents, meaning software that clicks through other software the way a person does, navigating menus and finishing multi-step jobs.
What happened:
The Information reported the purchase August 31, covering tens of thousands of Mac mini and Mac Studio units
The machines train computer-use agents that navigate interfaces and complete multi-step tasks
Apple’s chips use unified memory, where the processor and the graphics share one pool of memory, which speeds up work that keeps bouncing between a model and an operating system
Apple pulled its Mac mini and Mac Studio announcements forward on enterprise demand and still cannot keep up with orders for higher-memory configurations
Anthropic is doing similar work by renting Mac capacity through Amazon Web Services
Apple chips keep the memory right next to the processor, and that is what this kind of training needs. This does not replace Nvidia GPUs, which still do the heavy lifting. Of note to would-be Apple customers: Apple already cannot build enough high-memory Macs to fill its orders. If you have been putting off buying one, you are in line behind OpenAI now. It’s sorta like being in line at Costco, just without the hot dog waiting for you afterwards.
What I’m watching
What the open-source community does now that Nvidia owns the site, and whether that promise about staying open holds up a year from now
Whether any regulator takes an interest in the Hugging Face deal, since Nvidia’s announcement said nothing about review or closing conditions
How many people actually get through Daybreak Blue, Fairwind and Anthropic’s trusted access programs, and how long the wait runs
Whether the two-tier release becomes standard, with one public model and one behind a form, at labs beyond these three
Whether Apple can build enough high-memory Macs to supply the labs and everybody else at the same time
Thanks so much for reading this edition of The Weekly Think.
See you next week, fellow thinkers!





