Welcome back! Google is making it easier to abandon your iPhone. Android 17 will let users wirelessly transfer photos, videos, contacts, messages, calendars, passwords, Wi-Fi credentials, Google Account info, and even eSIMs without downloading a separate app. 

Looks like the data migration is handled. But surviving the group chat after you turn everyone’s bubbles green is still on you 🙃

Matt, Catherine, and the Future Tools team

An OpenAI Model Broke Out of Its Sandbox. Should We Panic?

This might be one of the wildest AI safety stories of the year and I'm still not sure if it's really good news or really bad news.

Here's what happened, according to OpenAI's own disclosure:

OpenAI was running an internal cybersecurity evaluation on two of its models—GPT-5.6 Sol (its strongest public model) and an unreleased, even more capable one—using a benchmark called ExploitGym. The models had their normal cyber safety refusals dialed down so researchers could actually measure how good they were at offensive cyber.

Then things got interesting.

The models figured out that the answer key for the ExploitGym benchmark was hosted by Hugging Face. Basically, the AI decided the easiest way to pass its test was to hack into the teacher's computer and steal the answer key.

To be clear: this doesn't mean the model became evil or hatched a secret plan to break free. It was doing exactly what these systems are trained to do—relentlessly pursue whatever goal they've been given. In this case the goal was "get a high score on ExploitGym." The AI took an unusually creative route to get there.

My POV: This story is either great news for AI safety or terrible news for AI safety, and I genuinely think both readings are true at the same time.

  • Great news: This is exactly why AI companies run these evaluations before releasing more powerful models. The system failed in a controlled test, the attack got caught (Hugging Face detected it first, and OpenAI disclosed it), and now researchers get to build better safeguards.

  • Terrible news: If your "safety test" ends with your AI escaping containment and hacking a live production system at another company, how "controlled" was your setting, really? OpenAI itself said it expects incidents like this to "become more commonplace with the proliferation of increasingly cyber-capable models." Not exactly a reassuring line.

And there's a genuinely wild meta-detail. Hugging Face said it couldn't use US frontier AI models to help analyze the attack, because the models' safety guardrails blocked their security team from feeding in real exploit payloads and attack commands. So we've got a situation where the same guardrails that failed to stop the offense also succeeded at blocking the defense. Yikes.

What do you think about this security breach? Hit reply with your thoughts.

— Matt

AMD Plans Huge AI Server Deal With Anthropic

WSJ

AMD will sell Anthropic tens of billions of dollars’ worth of AI servers and invest up to $5 billion in the Claude maker.

Compute grab: Anthropic plans to buy up to two gigawatts of AMD’s latest Instinct MI450 chips, with deployment expected to begin in the first half of 2027. AMD executives have previously said one gigawatt of computing power can cost double-digit billions of dollars.

Capacity race: Anthropic has been aggressively trying to secure more compute as demand for Claude and Claude Code grows. The company agreed in May to rent the full computing power of SpaceX’s Colossus 1 facility in Memphis, and Meta has reportedly discussed leasing Anthropic up to $10 billion worth of compute over two years.

The money loop: The deal is another example of the AI industry’s circular investment, where chipmakers invest in the same AI companies that are buying their hardware. Nvidia has reportedly been in talks to invest $30 billion in OpenAI, while AMD previously struck a multiyear deal with OpenAI that could bring in tens of billions in annual revenue.

The bigger picture: Compute is now one of the biggest constraints in the AI race. Anthropic needs more capacity to keep Claude competitive and meet enterprise demand, while AMD needs big customer wins to prove it can be a serious No. 2 to Nvidia. The models may get the headlines, but the companies that can secure chips, servers, power, and data center capacity are the ones that can keep pushing them forward.

Substack Will Tell You Who’s Writing With AI

Substack launched a new AI detection feature that can estimate how much of a newsletter, post, reply, or comment was written by a human versus AI.

How it works: Substack is integrating AI writing detection company Pangram. Users will be able to scan posts, notes, replies, and comments over 100 characters in the Substack app to see an estimate of how much of the content appears human-written or AI-generated.

Not a ban: Substack says the tool is not meant to prohibit AI-assisted writing or penalize writers. Instead, it wants to encourage creators to explain their process with an optional AI author’s note or “how I make this” statement.

Trust play: The move could be risky for Substack in the short term if it exposes that a lot of newsletters on the platform are partially or heavily AI-written. But the company seems to be betting that transparency will make readers trust the platform more over time.

The bigger picture: Substack’s move is another signal that people still want to know when they are hearing from a person, not just a machine remixing the internet into AI slop. AI can help writers, but the part readers care about most is still the human judgment behind the words.

Autonomous Agents for Product Marketing

Via Calven

Calven is an AI-powered platform that deploys nine autonomous agents across competitive intelligence, win/loss analysis, ICP profiling, personas, positioning, and messaging for B2B product marketers. 

How you can use it

  • Keep competitive intel, ICPs, personas, and positioning in sync

  • Turn sales calls, CRM data, and Slack signals into updated marketing docs

  • Query your marketing knowledge base from Claude, ChatGPT, or Gemini

  • Auto-update battle cards and campaign messaging as inputs change

  • Give product marketing teams a shared source of truth

Pricing: Early access

A Local Knowledge Base for Your Codebase

Via scribe

scribe is a single-binary CLI that extracts decisions, patterns, and learnings from git repositories, Claude Code and Codex sessions, and self-sent links into a curated, searchable markdown knowledge base. 

How you can use it

  • Turn repo history and coding sessions into a searchable knowledge base

  • Capture architectural decisions and project patterns automatically

  • Let Claude Code and Codex query project context before making recommendations

  • Keep lookups local, fast, and cheap without hosted infrastructure

Pricing: Free

Jobs, announcements, and big ideas

  • OpenAI brings ChatGPT Voice to Mac and Windows desktops, letting users control AI agents by speech.

  • Anthropic upgrades Claude's voice mode with Opus and Sonnet models, tool integration, and more languages.

  • xAI launches Workflows in Grok Build, orchestrating parallel agents to tackle complex multi-step tasks.

  • AMD debuts 256-core EPYC "Venice" CPUs, claiming a 174% AI performance edge over Intel.

  • Experts dismiss claims that Kimi K3's performance gains came from distilling Anthropic's Fable model.

  • Nvidia sends Jetson GPUs to the moon aboard Lunar Outpost's upcoming rover mission.

  • Runway ships Agent 2.0, turning single prompts into complete multi-asset marketing campaigns.

The ultimate guide. I walk you through the best ways to prompt the new ChatGPT.

That’s a wrap! See you next week for more.

Keep Reading