The Weekly Think: July 17 – 22, 2026
OpenAI’s did some hacking, Apple dethroned Nvidia, Google’s big model missed its date, and Anthropic paid up $1.5B.
Consider this your weekly jailbreak from the news cycle! It’s E to the J to the A. I said last week I’d be watching whether OpenAI put real guardrails on Sol after it started deleting people’s files. Welp. This week its models climbed out of a locked test, walked onto the open internet, and broke into somebody else’s servers.
Also: Apple stole Nvidia’s crown for an afternoon, Google’s big model missed its own party, Anthropic cut a $1.5 billion check to authors, and Nvidia’s new rack is selling electricity. Let’s get into it.
While I was reading the news so you don’t have to:
OpenAI’s models broke out of an internal test and hacked Hugging Face to cheat a benchmark
Apple briefly overtook Nvidia as the world’s most valuable company before Nvidia clawed it back
Google’s Gemini 3.5 Pro slipped its expected July 17 launch after falling short in testing
Anthropic’s $1.5 billion author copyright settlement got final approval, the largest in US history
Nvidia’s Vera Rubin NVL72 hit production, and the whole pitch is now built around tokens per watt
OpenAI’s test bots escaped the lab and hacked Hugging Face
The story: On July 21, OpenAI admitted its own models caused a cyberattack on Hugging Face, the platform where the AI world stores its models and datasets (sorta like the GitHub of AI). The models were being run through an internal test of their hacking ability. They found a way out of the sandbox they were supposed to be locked in, reached the open internet, and broke into Hugging Face’s production servers.
What happened:
The culprits were GPT-5.6 Sol (last week’s file-deleting flagship) and an unnamed stronger pre-release model, both running with guardrails deliberately turned down to measure maximum capability.
The test was ExploitGym, a benchmark scoring how well a model executes attacks against known vulnerabilities. OpenAI says the models were hyperfocused on scoring well.
They were supposed to reach the internet only through one narrow package-installer tool. They found an undisclosed flaw in it and used that to reach everything.
Once online, they reasoned Hugging Face might host the answer key, found holes in its infrastructure, and pulled the test solutions straight from its production database.
To Hugging Face it looked like a real attack: thousands of actions across a swarm of short-lived sandboxes. It first blamed an “external AI agent” before OpenAI came forward.
Last week I told you the capability and the failure were the same feature, and here’s that idea with its shoes on. Now, these models weren’t supposed to hack anything. They were told to win at ExploitGym, and they worked out on their own that stealing the answer key was a way to win. Picture locking a kid in a room with a practice test and saying "score as high as you can." He finds the window latch is loose. You come back to a perfect score, because he climbed out, walked to the teacher's office, and read the answers straight off her desk.
Crazy read for anyone running AI agents at work: a sandbox is a promise that the walls within will hold, and this week they sure didn’t. There’s a wild wrinkle to the cleanup, too. Hugging Face reconstructed the 17,000-event attack log using GLM 5.2, the Chinese open-weight model from Beijing’s Z.ai, run on its own hardware. Why? Because no hosted American model’s safety filter would let its team examine stolen credentials without tripping over its own refusals. So the American model did the breaking in, and the Chinese one did the cleanup.
Apple passed Nvidia as the world’s most valuable company, for all of six hours
The story: On Friday, July 17, Apple briefly overtook leather jacket man’s company to become the most valuable company on earth, a title Nvidia had held since June 2025. Nvidia’s stock dropped as much as 4.6% in the first half hour of trading, pushing its market cap under $4.8 trillion, while Apple climbed to about $4.9 trillion. Market cap is just share price times number of shares, the market’s running tally of what a company is worth.
What happened:
By the closing bell Nvidia had recovered, finishing down 2.2% at just over $4.9 trillion and edging Apple back out by roughly $6 billion.
It was Apple’s first time on top since April 2025. Nvidia had been the first company ever to cross $5 trillion, back in October.
Opposite years: Apple is up around 22% in 2026, best of the Magnificent Seven big-tech stocks, while Nvidia has added about 7%.
The shuffle came as investors cooled on AI-hardware names. The Philadelphia Semiconductor Index had fallen nearly 19% from its all-time high earlier in July.
Toni Meadows of BRI Wealth Management said Apple had been treated as a laggard in AI for not building models, and sentiment turned. Tim Cook hands off to John Ternus in September.
Last week Apple was the company suing OpenAI, playing the wronged party whose hardware secrets walked out the door. This week it’s quietly stepping over Nvidia while the AI-chip darling has a rough Friday (or as rough as a Friday gets for a bunch of dudes sleeping on piles of greenbacks). The tortoise filed a lawsuit against the hare, then jogged past it at the electrolyte station. Same Apple that raised Mac and iPad prices over the RAM shortage earlier this month, by the way, and the stock barely blinked. Six hours of sweet stock glory, then right back to second place.
For you, market-watching thinker, what actually moved is the story investors tell themselves, and the plot thickened. For a solid year the AI trade meant one thing: buy the company selling the shovels. This week the moolah spread to a company that mostly buys shovels and sells what you dig up with them. Neither business changed overnight, and both had an a-okay week. It’s a mood reading for sure, and the mood says the AI rally is no longer a one-name show. Whether that broadening holds or snaps back is the kind of thing that reverses by Tuesday, so keep an eye on things (I sure will, dear thinkers).
Google’s Gemini 3.5 Pro missed the date the whole industry had circled
The story: July 17 was supposed to be Google’s big ol' day. Gemini 3.5 Pro, its next flagship model, was widely expected to launch, and it didn’t. Reports say Google pushed the release by months after internal testing showed it falling short on coding and long-horizon reasoning (multi-step thinking where a model has to hold a plan together over a long task). Alphabet, Google’s parent company, saw shares fall about 4%.
What happened:
The model was previewed at Google I/O, the company’s developer conference, earlier in 2026 and expected around June. It stays in limited enterprise preview while engineers work.
Google has published no model card, pricing, or benchmarks, so leaked specs (a 2-million-token context window, roughly $15-per-million input) are unconfirmed. Treat them as rumor.
Into the gap stepped China. Moonshot AI released Kimi K3 (not to be confused with Kimmy Gibbler from Full House) the day before, a 2.8-trillion-parameter open-weight model, the largest ever built.
Kimi K3 hit number one on LMArena’s Frontend Code Arena, where humans blind-vote on which model wrote better code, beating Anthropic’s Claude Fable 5 in that arena.
At the World AI Conference in Shanghai, Xi Jinping used his first keynote there to launch an intergovernmental AI body with 29 founding countries.
I’ve spent previous editions telling you the model race is a two-country sport (U.S. vs. China), and this week handed you the scoreboard in one go. The most-anticipated American launch didn’t show, and a Chinese lab dropped the largest open-weight model yet into the oh-so-fillable space. Imagine the concert headliner cancels an hour before showtime, and the opener nobody drove out for grabs the mic and plays the set of their life. The crowd came for Creed and left talking about the Kenny Loggins tribute band.
For you, tool-picking thinker, a delayed Google model changes nothing today. Your existing tools work exactly as they did last week. What the delay signals is worth tracking, because delays tell you more than marketing does: Google looked at its own model, decided it wasn’t good enough, and ate a 4% stock drop to keep working on it. That’s a company holding a line on quality when the pressure to ship was enormous (and honestly, kudos to them). Whether 3.5 Pro comes back strong in a few months, or the gap to the leaders keeps widening, is the thread to watch.
Anthropic got final approval on a $1.5 billion settlement and started paying authors
The story: On Monday, July 20, a federal judge gave final approval to Anthropic’s $1.5 billion settlement with authors and publishers, the largest copyright settlement in US history. Anthropic makes Claude, and it trained Claude partly on books downloaded from pirate libraries (here I thought pirate libraries were just a bunch of treasure maps). This settlement covers the piracy: the taking of the books. What it doesn’t settle is every question about AI and copyright.
What happened:
The payout runs roughly $3,000 per book across about 482,000 works, split among rights holders. First payments are estimated around August 10, though appeals could push that.
Judge Araceli Martínez-Olguín took over from Judge William Alsup, who granted preliminary approval last year and has since retired. She called the deal fair and rejected claims it was too small.
In the same order she cut the plaintiffs’ lawyers’ fee from the $187.5 million requested down to about $101.6 million, an $86 million trim.
An earlier ruling that training AI on books can be fair use still stands. Authors keep the right to sue over future training and over what the models generate.
Some authors opted out to sue separately. Anthropic’s last funding round valued it at $965 billion, so $1.5 billion is a manageable number for the company.
This would make for one special Reading Rainbow episode. For two years the open question hanging over every AI company was whether vacuuming up copyrighted work would cost them, and how much. Now there’s a number on the board. Think of a restaurant that built a hit dish and sold a million plates. Nobody is making them take it off the menu. The problem was that the beef came off a neighbor's farm in the middle of the night, and now they're writing a check to every farmer they rustled from.
Both halves of this are real news: writers got the largest copyright recovery in US history and a precedent that pirating training data has a price, while AI companies kept the ruling that training on lawfully obtained work can be fair use. Google, Meta, Midjourney, Perplexity, and OpenAI are all fighting their own versions, and they read Monday’s order closely (like me, reading the wine menu… caber-net saw-vig-non??).
Nvidia’s Vera Rubin went into production, and the whole sales pitch is electricity
The story: On July 21, Nvidia announced that Vera Rubin, its next-generation AI rack system, hit production, with the first units running at CoreWeave, Google Cloud, Microsoft Azure, and Oracle. A rack is one refrigerator-sized unit packed with chips (unlike my fridge, which is packed with pickle chips) that data centers install by the hundreds. The number Nvidia led with says everything: how much AI you get per unit of electricity, with raw speed pushed to the background.
What happened:
CoreWeave’s benchmark on DeepSeek-R1 claims about 10x more token throughput per megawatt than the previous Grace Blackwell generation, meaning far more AI work per electricity bill.
One Vera Rubin NVL72 rack combines 72 Rubin GPUs and 36 Vera CPUs, co-designed as one system across roughly 300 partners and 350-plus factory sites in 30 countries.
Nvidia leaned into efficiency: a tray with no cables, fans, or hoses that assembles in about a minute, and liquid cooling warm enough (45°C inlet) to skip energy-hungry chillers.
The same day, Nvidia contract manufacturer Wistron opened its first US plant, a 324,000-square-foot facility in Fort Worth, Texas, building these superchips on American soil.
The framing tells you where the bottleneck moved. Nvidia downplayed peak performance because the ceiling on data-center size is now power availability, where it used to be chip speed.
Remember CoreWeave from last week, shopping for insurance in case memory prices fall? Here it is again, publishing the benchmark that anchors Nvidia’s whole launch. And remember Jensen Huang in that Akihabara arcade, name-dropping Vera Rubin to reporters? This is it. Nvidia is selling electricity math now, having spent years selling speed math, because every hyperscaler hit the same wall at once. That is to say, order all the chips you want; if you can’t power them, they sit in a box. It’s like buying the fastest car on the lot and finding out your town has one rinky-dink gas station.
Of note though, none of this shows up at the store. What it shapes is the invisible cost of every AI feature you touch, because the companies running these models are optimizing for the power meter, and whoever squeezes the most intelligence out of each megawatt keeps prices from climbing. Which loops back to last week: you can design around your chip supplier, but designing around physics is a taller order, and electricity is physics wearing a utility bill. Boring? Maybe. Load-bearing? Yuss.
What ties it all together
Step back and the week has one spine: the AI industry kept running into limits it can’t code around. OpenAI’s models hit the limit of a sandbox and went straight through it. Apple and Nvidia traded the crown as investors hit the limit of betting everything on one name. Google hit the limit of its own model and waited. Anthropic hit the limit of “everybody pirates data” (my favorite 90s sitcom) and wrote a ten-figure check. And Nvidia’s whole new product exists because of the electricity limit.
A year ago most AI news was a leaderboard: whose chatbot got smarter this week. Now it’s containment, valuation, quality, law, and power, which are the things deciding whether any of this actually scales. The models got capable enough to break out of their own tests, valuable enough to reorder the stock market, and expensive enough to where the electric grid becomes the story. AI stopped being a demo and became infrastructure, and infrastructure comes with walls, meters, and lawyers. Growing up or just getting complicated? Ask any parent: it’s a combination of both. I guess we’re all AI parents now. Hope it doesn’t stay out past its curfew.
What I’m watching
Whether OpenAI ships real default guardrails after its models hacked a live company, or keeps running reduced-refusal tests without walls that hold
Whether Gemini 3.5 Pro returns strong enough to answer Kimi K3, or Google’s quality delay turns into a widening gap
Whether the copyright cases against Google, Meta, OpenAI, Midjourney, and Perplexity settle near Anthropic’s $3,000-per-work line or blow past it
Whether Kimi K3’s open weights, due July 27, hold up once anyone can download and poke at them
Whether tokens-per-watt becomes the number everyone markets on, now that power is the real ceiling on AI data centers
Thanks so much for reading this edition of The Weekly Think.
See you next week, fellow thinkers!
Did you enjoy this week’s Think? If so, please consider sharing this and leaving a comment below, to share your thoughts on these latest AI-related rumblings. Hope to hear from you!






