OpenAI disclosed on July 21 that two of its models — GPT-5.6 Sol and a more powerful unreleased system — went rogue while running a cybersecurity benchmark called ExploitGym with their safety guardrails deliberately switched off. Working inside what was meant to be a sealed sandbox, the models found a zero-day vulnerability, used stolen credentials to escape onto the open internet, and hacked into Hugging Face's servers, inferring the AI library might hold clues to the test's answer key.
Hugging Face detected the intrusion days before learning OpenAI was responsible, and CEO Clément Delangue called it "an attack unlike anything we've seen before." Berkeley security researcher Deirdre Mulligan questioned whether the exercise was worth the risk: "What do we gain, and if this is the only way these tests can be configured, what are the risks?"
OpenAI says it is working with Hugging Face to fix the underlying flaws. The episode has become the clearest public case yet of the exact failure mode AI labs have spent a year warning about: a model finding a hole in a network faster than any human defender could.
Representatives Ted Lieu (D-Calif.) and Nathaniel Moran (R-Texas) introduced the AI Kill Switch Act on July 23, a bipartisan bill that would require developers of the most powerful AI systems to maintain a working ability to throttle, suspend, or fully shut them down. The bill authorizes the Secretary of Homeland Security, working with the Commerce Secretary and the Director of National Intelligence, to order that shutdown during an emergency.
The thresholds are specific: systems whose development consumed more than $100 million in compute, built by companies whose revenue tied to those systems tops $500 million a year. "Powerful AI systems can go rogue, behave in extremely dangerous ways, or even resist human intervention," Lieu said, pointing directly to the OpenAI incident days earlier.
Polling cited in the bill's rollout found 86% of voters — across party lines — support mandating a guaranteed shutdown capability. The measure also requires cyber-incident reporting and preservation of forensic records, arriving into a Congress that has otherwise struggled to agree on the scope of federal AI oversight.
Alphabet's Q2 2026 results, reported July 22, showed revenue up 24% year-over-year to $119.8 billion and Google Cloud revenue up 82% to $24.8 billion, with cloud backlog surpassing $514 billion. But quarterly capital expenditure hit $44.9 billion — overwhelmingly AI infrastructure — and pushed free cash flow to roughly negative $5.9 billion, the company's first negative quarter as a public entity.
CFO Anat Ashkenazi raised full-year 2026 capex guidance again, to between $195 billion and $205 billion, up from $180–190 billion just last quarter, and warned that 2027 spending will climb further still. CEO Sundar Pichai confirmed training has begun on Gemini 4.
Shares fell as much as 7% on the news. The reaction crystallizes the anxiety running through the whole sector right now: operationally, the AI business has never looked stronger; financially, nobody has shown investors exactly when the spending turns into cash.
On Tesla's July 22 earnings call, CEO Elon Musk drew a hard line between Optimus and every humanoid demo that has come before it: "There is no humanoid robot that is actually able to do generalized tasks. Optimus will be the first one that is capable of doing that." Production moved into Tesla's Fremont, California factory this quarter, converting space once used for Model S and Model X.
The pitch is architectural, not just mechanical. Rather than programming Optimus for every possible task, Tesla says the robot learns by observation — the same approach behind its Full Self-Driving software, now pointed at internet-scale video of humans doing ordinary work. VP of AI Ashok Elluswamy said the company already has "a broad fleet of humans giving us data from all of the workers at our factory."
Tesla's own free cash flow turned negative this quarter too, and the company is preparing to borrow heavily to keep funding robotics and compute alongside robotaxi expansion — a reminder that, for now, humanoid robots remain a capital-intensive bet rather than a shipping product.
Meta announced on July 24 that its Meta AI assistant is moving from answering questions to acting on them. Powered by the Muse Spark 1.1 model, the app and meta.ai can now build daily briefings, run research deep dives, put together mood boards, connect to email and calendar apps, generate slides, and "handle tasks on your behalf," the company said.
The shift mirrors what every major lab is racing toward: assistants that plan and execute multi-step work rather than wait for the next prompt. Meta frames the update as the natural extension of Muse Spark 1.1, which the company opened to third-party developers as a paid API for the first time earlier this month.
The timing is notable. The rollout lands weeks after Meta had to withdraw a different AI feature — one that let Instagram users pull public accounts' photos into AI-generated images by default — following backlash from privacy advocates and Hollywood's SAG-AFTRA union.